CVE WATCH / VULNERABILITY DETAIL

CVE-2026-84718

MEDIUMCVSS 4.3NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacke

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-84718 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-84718

MEDIUMCVSS 4.3NVD feed

Published 23 September 2026 · tracked since 24 September 2026

Description

A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from a trusted proxy, and selects the leftmost (attacke

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]