CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-84719 — A flaw was found in the Ansible Automation Platform automation-controller. When ...

·Source: NIST NVD

Updated:

Executive Summary

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permiss

Analysis

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that were preserved from the original. A user with organization workflow-admin permission but no role on the referenced instance groups can copy a workflow, become its administrator, and launch jobs pinned to instance groups they are not authorized to use — including the control-plane instance group — bypassing the InstanceGroup use_role boundary and causing attacker-influenced automation to run in the control-plane execution context. CVSS Score: 9.9. Published: 2026-09-23T20:17:18.617.

Indicators of Compromise (1)

CVE (1)
CVE-2026-84719
Source Attribution

Originally published by NIST NVD on Sep 23, 2026. Verified by: NIST.

Related Threats

CRITICALVulnerability

NVD CRITICAL: CVE-2026-100721 — vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module...

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `require.external` with a custom resolver (and `context: 'host'`), `LegacyResolver.customResolve` in lib/resolver-compat.js records the resolved module directory in `this.externals` as `new RegExp('^' + escapeRegExp(resolvedPath))`, without requiring a path separator or end-of-str

CVE-2026-100721
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-100740 — A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the funct...

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

CVE-2026-100740
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-82901 — The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitr...

The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file type validation in the 'uacf7_wpcf7_mail_components' function in all versions up to, and including, 3.5.50. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: This is o

CVE-2026-82901
NIST NVD