CVE-2026-84716: Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames

Published Sep 2, 2026
·
Updated

A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certificate with the receptor mesh certificate authority in which the Common Name, DNS subject-alternative-name, and receptor node-id are taken verbatim from the caller-chosen instance hostname, with a hard-coded ten-year validity, a random serial, and no issuance log or revocation list. Because the hostname charset validator is case-insensitive while the uniqueness validator is case-sensitive, an administrator can register a case variant of an existing control node's hostname and obtain a mesh-CA-signed certificate that TLS peers, which match hostnames case-insensitively, accept as that control node. In managed/hosted deployments — where the customer holds controller superuser but the platform operator runs the mesh — this yields a long-lived, non-revocable mesh peer credential and, with an on-path position, TLS impersonation or interception of control/hybrid mesh nodes. It does not grant direct remote code execution, because receptor work submission is gated by a separate signing key not included in the bundle.

Other sources

A privilege/trust-boundary flaw was found in the automation-controller instance install-bundle feature. The endpoint GET /api/controller/v2/instances/{id}/ installbundle/, restricted to System Administrators, returns a tarball containing a newly generated private key and an X.509 certificate signed by the receptor mesh certificate authority. The certificate's Common Name, DNS subject-alternative-name, and receptor node-id extension are copied verbatim from the instance's hostname, which the administrator chose freely when creating the instance; the certificate is hard-coded to a ten-year validity, uses a random serial number, and is never recorded in any issuance log or certificate revocation list, so it cannot be revoked without rotating the mesh CA across the entire fleet. Furthermore, the controller validates the hostname charset case-insensitively but enforces uniqueness case-sensitively, so an administrator can register a case variant of an existing control node's hostname — for example Controller.aap.svc alongside controller.aap.svc — and receive a mesh-CA-signed certificate whose DNS name TLS verifiers, which compare hostnames case-insensitively, accept as the genuine control node. The security significance depends on the deployment model. On a self-managed installation a System Administrator already controls the host that stores the mesh CA key, so minting a certificate is not an escalation. In a managed or hosted deployment, however, the customer holds controller superuser while the platform operator runs the mesh; there the flaw lets a customer-tier administrator obtain a long-lived, non-revocable mesh peer credential and, with an on-path network position, impersonate or intercept traffic to control and hybrid nodes at the TLS layer. The certificate does not grant direct code execution on mesh nodes, because receptor work submission is protected by a separate work-signing key whose private half is not distributed in the bundle.

— Red Hat

Affected Software

1 affected component
Red Hat automation-controller

Event History

Sep 2, 2026
Data Sourced
via Red Hat·01:06 AM
DescriptionSeverityAffected Software
Sep 23, 2026
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can obtain an affected credential?

A System Administrator who can download an execution or hop node install bundle can cause the controller to issue the certificate. Managed or hosted deployments are particularly exposed when the customer has controller superuser access while the platform operator operates the receptor mesh.

2

What is required to impersonate or intercept a mesh peer?

The attacker needs a mesh-CA-signed certificate for a case-variant hostname of an existing control node and an on-path position. TLS peers match hostnames case-insensitively, allowing the case-variant certificate to be accepted as the targeted control node.

3

Can certificates issued through this path be revoked or readily audited?

The certificates have a hard-coded ten-year validity and there is no revocation list, so they are non-revocable through a CRL. The endpoint also has no issuance log, limiting the ability to audit whether suspicious certificates were issued.

4

Does possession of this certificate provide direct remote code execution?

No. Receptor work submission is gated by a separate signing key that is not included in the issued certificate.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203