{"dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": {"cveId": "CVE-2026-84486", "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "state": "PUBLISHED", "assignerShortName": "redhat", "dateReserved": "2026-09-01T20:41:23.322Z", "datePublished": "2026-09-23T18:35:50.890Z", "dateUpdated": "2026-09-23T21:46:07.224Z"}, "containers": {"cna": {"title": "Automation-controller: automation-controller-container: automation-controller: unauthenticated debug scheduler-trigger endpoints (allowany, routed without debug guard) allow advisory-lock starvation of job dispatch (dos)", "metrics": [{"other": {"content": {"value": "Important", "namespace": "https://access.redhat.com/security/updates/classification/"}, "type": "Red Hat severity rating"}}, {"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "HIGH", "baseScore": 8.2, "baseSeverity": "HIGH", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H", "version": "3.1"}, "format": "CVSS"}], "descriptions": [{"lang": "en", "value": "A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Four debug views that trigger the internal task, dependency, and\nworkflow schedulers are configured to allow any user (including unauthenticated\nclients) and are routed in production builds because their URL include is not\ngated on the debug setting. An unauthenticated remote attacker can repeatedly\ninvoke these endpoints to acquire the cluster-wide scheduler advisory lock;\nbecause the legitimate scheduler acquires the same lock without waiting, the\nattacker causes real scheduler runs to be skipped, stalling job dispatch for\nall tenants, while also consuming controller web workers. The debug root view\nadditionally discloses the list of debug endpoints to unauthenticated callers."}], "affected": [{"vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2.6 for RHEL 9", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "automation-controller", "defaultStatus": "affected", "versions": [{"version": "0:4.7.17-1.el9ap", "lessThan": "*", "versionType": "rpm", "status": "unaffected"}], "cpes": ["cpe:/a:redhat:ansible_automation_platform:2.6::el10", "cpe:/a:redhat:ansible_automation_platform:2.6::el9", "cpe:/a:redhat:ansible_automation_platform_developer:2.6::el10", "cpe:/a:redhat:ansible_automation_platform_developer:2.6::el9", "cpe:/a:redhat:ansible_automation_platform_inside:2.6::el9"]}, {"vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "ansible-automation-platform-26/controller-rhel9", "defaultStatus": "affected", "cpes": ["cpe:/a:redhat:ansible_automation_platform:2"]}, {"vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "ansible-automation-platform-27/controller-rhel9", "defaultStatus": "affected", "cpes": ["cpe:/a:redhat:ansible_automation_platform:2"]}], "references": [{"url": "https://access.redhat.com/errata/RHSA-2026:71113", "name": "RHSA-2026:71113", "tags": ["vendor-advisory", "x_refsource_REDHAT"]}, {"url": "https://access.redhat.com/security/cve/CVE-2026-84486", "tags": ["vdb-entry", "x_refsource_REDHAT"]}, {"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2527085", "name": "RHBZ#2527085", "tags": ["issue-tracking", "x_refsource_REDHAT"]}], "datePublic": "2026-09-23T00:00:00.000Z", "problemTypes": [{"descriptions": [{"cweId": "CWE-489", "description": "Active Debug Code", "lang": "en", "type": "CWE"}]}], "x_redhatCweChain": "CWE-489: Active Debug Code", "timeline": [{"lang": "en", "time": "2026-09-01T20:42:20.853Z", "value": "Reported to Red Hat."}, {"lang": "en", "time": "2026-09-23T00:00:00.000Z", "value": "Made public."}], "providerMetadata": {"orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat", "dateUpdated": "2026-09-23T21:46:07.224Z"}, "x_generator": {"engine": "cvelib 1.8.0"}}, "adp": [{"metrics": [{"other": {"type": "ssvc", "content": {"timestamp": "2026-09-23T19:26:33.390389Z", "id": "CVE-2026-84486", "options": [{"Exploitation": "none"}, {"Automatable": "yes"}, {"Technical Impact": "partial"}], "role": "CISA Coordinator", "version": "2.0.3"}}}], "title": "CISA ADP Vulnrichment", "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-23T19:41:49.501Z"}}]}}