CVE-2026-84711 is an argument-injection vulnerability in Red Hat Ansible Automation Controller project synchronization. Attacker-controlled Project scm_branch or scm_refspec values can be interpreted as Git arguments during a project sync, rather than solely as a branch or refspec. This permits arbitrary file reads from the host performing the synchronization. Affected releases include Ansible Automation Platform 2.4, 2.5, and 2.6 Automation Controller deployments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Git argument injection through a Project scm_branch can permit arbitrary file reads in Automation Controller.
An arbitrary-file-read flaw in automation-controller caused by argument injection through Project scm_branch or scm_refspec values during Git project synchronization. It may expose sensitive files on the synchronization host, including control-plane service-account tokens, SECRET_KEY values, and database credentials.
Automation Controller arbitrary-file-read vulnerability through Git argument injection in Project scm_branch or scm_refspec.
Git argument injection through Project scm_branch or scm_refspec permits arbitrary file reads on the project-sync host.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.