VYPR
Critical severity9.6NVD Advisory· Published Sep 23, 2026

automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them

CVE-2026-84684

Description

automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.