Bug 2527199 (CVE-2026-84716) - CVE-2026-84716 automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-CA certificates for caller-chosen (and case-variant impersonating) hostnames
Summary: CVE-2026-84716 automation-controller: automation-controller: instance install...
Keywords:
Status: NEW
Alias: CVE-2026-84716
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-02 01:06 UTC by OSIDB Bzimport
Modified: 2026-09-23 21:08 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:71113 0 None None None 2026-09-23 20:51:30 UTC
Red Hat Product Errata RHSA-2026:71114 0 None None None 2026-09-23 21:08:06 UTC

Description OSIDB Bzimport 2026-09-02 01:06:32 UTC
A privilege/trust-boundary flaw was found in the automation-controller instance
  install-bundle feature. The endpoint GET /api/controller/v2/instances/{id}/
  install_bundle/, restricted to System Administrators, returns a tarball
  containing a newly generated private key and an X.509 certificate signed by the
  receptor mesh certificate authority. The certificate's Common Name, DNS
  subject-alternative-name, and receptor node-id extension are copied verbatim
  from the instance's hostname, which the administrator chose freely when creating
  the instance; the certificate is hard-coded to a ten-year validity, uses a
  random serial number, and is never recorded in any issuance log or certificate
  revocation list, so it cannot be revoked without rotating the mesh CA across the
  entire fleet. Furthermore, the controller validates the hostname charset
  case-insensitively but enforces uniqueness case-sensitively, so an administrator
  can register a case variant of an existing control node's hostname — for
  example Controller.aap.svc alongside controller.aap.svc — and receive a
  mesh-CA-signed certificate whose DNS name TLS verifiers, which compare hostnames
  case-insensitively, accept as the genuine control node. The security
  significance depends on the deployment model. On a self-managed installation a
  System Administrator already controls the host that stores the mesh CA key, so
  minting a certificate is not an escalation. In a managed or hosted deployment,
  however, the customer holds controller superuser while the platform operator
  runs the mesh; there the flaw lets a customer-tier administrator obtain a
  long-lived, non-revocable mesh peer credential and, with an on-path network
  position, impersonate or intercept traffic to control and hybrid nodes at the
  TLS layer. The certificate does not grant direct code execution on mesh nodes,
  because receptor work submission is protected by a separate work-signing key
  whose private half is not distributed in the bundle.

Comment 2 Jon Orris 2026-09-23 20:51:29 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 3 Jon Orris 2026-09-23 21:08:05 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114


Note You need to log in before you can comment on or make changes to this bug.