Bug 2527222 (CVE-2026-84724) - CVE-2026-84724 automation-controller: automation-controller: SystemJob extra_vars.days argument injection into uncontainerized control-plane awx-manage process
Summary: CVE-2026-84724 automation-controller: automation-controller: SystemJob extra_...
Keywords:
Status: NEW
Alias: CVE-2026-84724
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-02 01:58 UTC by Thomas Eagle
Modified: 2026-09-23 21:08 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:71113 0 None None None 2026-09-23 20:51:37 UTC
Red Hat Product Errata RHSA-2026:71114 0 None None None 2026-09-23 21:08:12 UTC

Description Thomas Eagle 2026-09-02 01:58:42 UTC
A flaw was found in the Ansible Automation Platform automation-controller system-job dispatcher.
SystemJobTemplateLaunch.post (awx/api/views/__init__.py:3802-3805) calls create_unified_job with
the request's extra_vars directly and never invokes _accept_or_ignore_job_kwargs, so the "days"
integer validator in SystemJobTemplate._accept_or_ignore_variables (awx/main/models/jobs.py:
1234-1245) is not applied on the launch path; create_unified_job (awx/main/models/unified_jobs.py:
369-400) copies the extra_vars dict onto the SystemJob verbatim after checking only key names.
RunSystemJob.build_args (awx/main/tasks/jobs.py:2113-2134) then appends str(days) to the
awx-manage argument list without integer coercion, and RunSystemJob.write_args_file (jobs.py:
2136-2137) writes ' '.join(args) to the ansible-runner args file, which ansible-runner re-tokenizes
with shlex.split. A "days" value such as "5 --pythonpath /path" therefore splits into extra
awx-manage arguments. RunSystemJob.build_execution_environment_params returns {} (jobs.py:2110-2111)
and the dispatcher runs ansible_runner.interface.run() in-process for SystemJob instances
(jobs.py:773-781) — system jobs are the only unified-job class executed without receptor/podman
isolation — so the injected arguments reach an uncontainerized control-plane awx-manage process
running as the awx user with access to SECRET_KEY, database credentials, and the receptor control
socket. Django's handle_default_options parses global options such as --pythonpath from the
argument vector and inserts the attacker-supplied directory at the front of sys.path. Only a
superuser can trigger this (SystemJobTemplateAccess.can_start is decorated @check_superuser,
awx/main/access.py:1770-1773). Full code execution additionally requires a top-level module
imported for the first time after handle_default_options; no such import exists in the current
cleanup_jobs / cleanup_activitystream import graph, so the issue is confirmed as argument injection
with control of the process argument vector and sys.path[0], with code execution unproven.

    Upstream: https://github.com/ansible/tower (awx)
    Affected file: awx/main/tasks/jobs.py:2136-2137 (RunSystemJob.write_args_file — ' '.join(args),
                   root cause); jobs.py:2113-2134 (build_args, no int() coercion); jobs.py:
                   2110-2111 + 773-781 (uncontainerized in-process execution);

Comment 2 Jon Orris 2026-09-23 20:51:36 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 3 Jon Orris 2026-09-23 21:08:10 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114


Note You need to log in before you can comment on or make changes to this bug.