Threat Overview
Red Hat published Ansible Automation Platform security updates on September 23-24 covering three critical authorization and isolation failures that can cross trust boundaries inside automation infrastructure. CVE-2026-84474 and CVE-2026-84719 are rated CVSS 9.9, while CVE-2026-75884 is rated CVSS 9.1.
CVE-2026-84474 can expose a provisioning-callback secret and, under the documented proxy configuration, allow an attacker with the secret to impersonate an inventory host and launch a job template against managed systems using existing template credentials. CVE-2026-84719 can allow an organization workflow administrator to preserve unauthorized instance-group references when copying workflows. CVE-2026-75884 can allow an AAP platform administrator to abuse container-group pod configuration and escalate Kubernetes/OpenShift namespace access.
References
- Red Hat CVE-2026-84474 and associated September 23-24 security advisories: https://access.redhat.com/security/cve/CVE-2026-84474
- Red Hat CVE-2026-84719: https://access.redhat.com/security/cve/CVE-2026-84719
- Red Hat CVE-2026-75884: https://access.redhat.com/security/cve/CVE-2026-75884
Impacted Systems
Red Hat Ansible Automation Platform automation-controller/AWX-derived components across supported AAP 2.x branches covered by the September 23-24 advisories, including RHEL 8/RHEL 9 RPM deployments and containerized/OpenShift deployments depending on branch. Red Hat published fixes through applicable AAP 2.4, 2.5, 2.6, and 2.7 security advisories. Exact package builds differ by supported branch.
Why this matters
AAP can execute privileged automation across large server estates and commonly stores or uses credentials for managed hosts, cloud platforms, network devices, and deployment systems. Authorization bypass or control-plane execution can turn one AAP account or controller weakness into code execution across downstream infrastructure.
Exploitation Status
No confirmed in-the-wild exploitation was identified in the authoritative sources reviewed as of September 25. These are newly disclosed and patched critical vulnerabilities, so this is a high-priority patch, exposure-review, and behavioral-hunting case rather than an active-exploitation claim.
What this hunt looks for
Unusual Ansible/AWX job execution, unexpected automation from controller processes, shell or downloader execution associated with Ansible/Python, new outbound destinations, Kubernetes/OpenShift command activity, secret access, and privilege or persistence changes on managed hosts.
Required logs
Microsoft Defender endpoint telemetry, Linux Syslog, Windows Security Events where managed Windows hosts are relevant, and native AAP audit/API logs where available.
First Pass – Ansible or AWX Associated Shell and Downloader Execution
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("python","python3","ansible","ansible-playbook","awx-manage")
| where FileName in~ ("sh","bash","dash","curl","wget","powershell.exe","pwsh.exe","cmd.exe","kubectl","oc")
| project Timestamp,DeviceName,AccountName,InitiatingProcessFileName,InitiatingProcessCommandLine,FileName,ProcessCommandLine,SHA256
| order by Timestamp desc
Ansible and AWX Activity in Linux Syslog
Syslog
| where TimeGenerated >= ago(30d)
| where ProcessName has_any ("ansible","awx","python") or SyslogMessage has_any ("ansible","awx","automation-controller")
| project TimeGenerated,Computer,HostName,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc
Automation Processes Reaching New Destinations
let Baseline=DeviceNetworkEvents
| where Timestamp between (ago(30d)..ago(7d))
| where InitiatingProcessFileName in~ ("python","python3","ansible","ansible-playbook","awx-manage")
| summarize by DeviceId,RemoteIP,RemoteUrl;
DeviceNetworkEvents
| where Timestamp >= ago(7d)
| where InitiatingProcessFileName in~ ("python","python3","ansible","ansible-playbook","awx-manage")
| join kind=leftanti Baseline on DeviceId,RemoteIP,RemoteUrl
| project Timestamp,DeviceName,InitiatingProcessFileName,InitiatingProcessCommandLine,RemoteUrl,RemoteIP,RemotePort
| order by Timestamp desc
Kubernetes and OpenShift CLI from Automation Processes
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where FileName in~ ("kubectl","oc")
| where InitiatingProcessFileName in~ ("python","python3","ansible","ansible-playbook","awx-manage","sh","bash")
| project Timestamp,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by Timestamp desc
Secret and Service Account Access Commands
DeviceProcessEvents
| where Timestamp >= ago(30d)
| where FileName in~ ("kubectl","oc")
| where ProcessCommandLine has_any ("secret","secrets","serviceaccount","service-account","token")
| project Timestamp,DeviceName,AccountName,FileName,ProcessCommandLine,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by Timestamp desc
Automation-Associated File Creation
DeviceFileEvents
| where Timestamp >= ago(30d)
| where InitiatingProcessFileName in~ ("python","python3","ansible","ansible-playbook","awx-manage")
| where ActionType in~ ("FileCreated","FileModified")
| where FileName endswith ".sh" or FileName endswith ".py" or FileName endswith ".ps1" or FileName endswith ".service"
| project Timestamp,DeviceName,ActionType,FileName,FolderPath,SHA256,InitiatingProcessFileName,InitiatingProcessCommandLine
| order by Timestamp desc
Linux Privilege and Persistence Changes Near Automation Activity
Syslog
| where TimeGenerated >= ago(30d)
| where SyslogMessage has_any ("sudo","useradd","usermod","groupadd","systemctl","crontab","authorized_keys")
| where SyslogMessage has_any ("ansible","awx","python","automation")
| project TimeGenerated,Computer,HostName,ProcessName,SeverityLevel,SyslogMessage
| order by TimeGenerated desc
Windows Service Creation on Managed Hosts
SecurityEvent
| where TimeGenerated >= ago(30d)
| where EventID == 4697
| project TimeGenerated,Computer,Account,Activity,EventData
| order by TimeGenerated desc
Detection Notes
AAP is designed to execute commands at scale, so many process, file, and network behaviors can be legitimate automation. Baseline job schedules, controller identities, execution nodes, and approved managed-host groups before escalating. Native AAP audit events are the best source for proving who copied a workflow, accessed a job template, invoked a provisioning callback, or modified a container group. CVE-2026-84474 is especially difficult to distinguish without AAP audit/API logs because resulting managed-host execution may use legitimate stored credentials and normal Ansible execution paths.