VYPR
Moderate severity6.5NVD Advisory· Published Sep 23, 2026

automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output (cross-tenant information disclosure)

CVE-2026-84707

Description

automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output (cross-tenant information disclosure)

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.