CVE-2026-84638 is an authorization flaw in Red Hat Ansible Automation Controller/AWX instance-group attachment handling. When attaching an instance group to a Schedule or WorkflowJobTemplateNode, the controller verifies only read permission on the instance group rather than enforcing the authorization required to assign it. A user with read access can therefore associate a restricted instance group with scheduling or workflow execution objects.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Schedule and workflow-node attachment enables instance-group privilege escalation in Automation Controller.
A privilege-escalation flaw in automation-controller that checks only read permission when attaching instance groups to schedules or workflow job-template nodes, enabling use of restricted instance groups, including control-plane or other-tenant groups.
Automation Controller instance-group privilege escalation caused by insufficient authorization for schedule and workflow-node attachment.
Instance-group attachment checks only read permission, allowing use of restricted instance groups such as control-plane or other-tenant groups.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.