VYPR
Moderate severity4.9NVD Advisory· Published Sep 23, 2026

automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via /api/controller/v2/credential_types/

CVE-2026-84709

Description

automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via /api/controller/v2/credential_types/

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.