Skip to main content
CRITICAL

CVE-2026-84502

CVSS v3

9.9

CRITICAL

EPSS Score

0.6 %

exploit probability, as of 2026-09-28

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--" separator, a git project URL such as "--upload-pack=<command>:x" is interpreted by git as the --upload-pack option and executed via a shell. A user with permission to create or modify a

Technical details

Published
2026-09-23
Last Modified
2026-09-24

Frequently asked questions

What is CVE-2026-84502?

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--" separator, a git project URL such as "--upload-pack=<command>:x" is interpreted by git as the --upload-pack option and executed via a shell. A user with permission to create or modify a

Is CVE-2026-84502 actively exploited?

Active exploitation of CVE-2026-84502 has not been confirmed. Its EPSS score was 0.6% on 2026-09-28, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-84502?

CVE-2026-84502 has a CVSS v3 base score of 9.9 (CRITICAL severity).

Is CVE-2026-84502 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key