VYPR

automation-controller-container

by Automation Controller

CVEs (14)

  • CVE-2026-84711criSep 23, 2026
    risk 0.64cvss 9.9epss

    automation-controller: automation-controller: Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to…

  • CVE-2026-84638criSep 23, 2026
    risk 0.64cvss 9.9epss

    automation-controller: automation-controller-container: automation-controller: instance group attachment to schedules and workflow job template nodes checks only read permission, allowing use of restricted (controlplane / other-tenant) instance groups and privilege escalation to…

  • CVE-2026-84684criSep 23, 2026
    risk 0.62cvss 9.6epss

    automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands…

  • CVE-2026-84708impSep 23, 2026
    risk 0.57cvss 8.7epss

    automation-controller: automation-controller-container: automation-controller: container group pod_spec_override mints the automation-controller ServiceAccount token and mounts control-plane namespace secrets into job pods, bypassing automountServiceAccountToken:false…

  • CVE-2026-84678impSep 23, 2026
    risk 0.57cvss 8.7epss

    automation-controller: automation-controller-container: automation-controller: GALAXY_TASK_ENV setting is not filtered for dynamic-linker / interpreter environment variables, allowing a system administrator to achieve code execution in the project-update execution environment

  • CVE-2026-84692impSep 23, 2026
    risk 0.55cvss 8.5epss

    automation-controller: automation-controller-container: automation-controller: workflow job template node execute permission check bypassed by creating a node with a null unified_job_template and then patching it, allowing a single workflow-admin to execute any other tenant's…

  • CVE-2026-84689impSep 23, 2026
    risk 0.55cvss 8.5epss

    automation-controller: automation-controller-container: automation-controller: bulk job launch allows setting a workflow node's job reference to an arbitrary unified job, enabling a low-privileged user to cancel and read metadata of jobs in other organizations

  • CVE-2026-84475impSep 23, 2026
    risk 0.50cvss 7.7epss

    automation-controller: automation-controller-container: automation-controller: InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle

  • CVE-2026-84686impSep 23, 2026
    risk 0.49cvss 7.6epss

    automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS and…

  • CVE-2026-84703modSep 23, 2026
    risk 0.44cvss 6.8epss

    automation-controller: automation-controller-container: automation-controller: execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry…

  • CVE-2026-84707modSep 23, 2026
    risk 0.42cvss 6.5epss

    automation-controller: automation-controller-container: automation-controller: host_filter SmartFilter ORM traversal exposes JobEvent/AdHocCommandEvent event_data and stdout to users without permission on the job, enabling blind character-by-character extraction of job output…

  • CVE-2026-84643modSep 23, 2026
    risk 0.33cvss 5.0epss

    automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant

  • CVE-2026-84709modSep 23, 2026
    risk 0.32cvss 4.9epss

    automation-controller: automation-controller: CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption (denial of service) and an unhandled-exception (500) via…

  • CVE-2026-84680modSep 23, 2026
    risk 0.27cvss 4.1epss

    automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's…