Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2982 articles · 185103 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-11332EXPLOITEDPATCHED
red hat · ansible-core

Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

Description

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

Affected Products

VendorProductVersions
red hatansible-core—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
pipansible-coreGHSA85%
red hatansible automationcert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:42078(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:42079(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:42080(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:46836(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50340(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50344(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50357(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50479(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-11332(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2485379(issue-tracking, x_refsource_REDHAT)
  • https://github.com/ansible/ansible

Related News (5 articles)

Tier B
BSI Advisories3d ago
[NEU] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier B
BSI Advisories61d ago
[UPDATE] [mittel] Ansible: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode und Offenlegung von Daten
→ No new info (linked only)
Tier B
BSI Advisories61d ago
[UPDATE] [mittel] Ansible: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
→ No new info (linked only)
Tier A
Microsoft MSRC62d ago
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
→ No new info (linked only)
Tier C
VulDB64d ago
CVE-2026-11332 | Red Hat Ansible Automation Platform 2 ansible-core meta/requirements.yml src argument injection
→ No new info (linked only)
CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
ansible-core@2.16.19rc1ansible-core@2.18.18rc1ansible-core@2.19.11rc1ansible-core@2.20.7rc1ansible-core@2.21.1rc1
CWECWE-88
PublishedJun 5, 2026
Last enriched61d agov3
Trending Score35
Source articles5
Independent3
Info Completeness8/14
Missing: versions, epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-4480EXPKEV
Samba: samba: remote code execution in printing subsystem via unescaped job description
Trending: 80
HIGHCVE-2026-42170EXP
Gimp: gimp dds plug-in heap-based buffer overflow via bpp mismatch in load_layer() (ddsread.c)
Trending: 44
NONECVE-2026-18649EXP
Gst-plugins-good: gst-plugins-good: unbounded memory growth in rtph264depay and rtph265depay rtp depayloaders
Trending: 39
NONECVE-2026-4408
Samba: remote code execution in samr
Trending: 33
NONECVE-2026-3012
Samba: group policy certificate enrollment uses http:// without validation
Trending: 33

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 5, 2026
Discovered by ZDM
Jun 5, 2026
Updated: severity
Jun 5, 2026
Updated: severity, exploitAvailable, activelyExploited
Jun 8, 2026
Actively Exploited
Aug 7, 2026
Exploit Available
Aug 7, 2026
Patch Available
Aug 7, 2026

Version History

v3
Last enriched 61d ago
v3Tier B61d ago

Updated severity to HIGH and marked the vulnerability as actively exploited with an exploit available.

severityexploitAvailableactivelyExploited
via BSI Advisories
v2Tier C64d ago

Updated severity to CRITICAL and corrected exploit availability to false.

severity
via VulDB
v164d ago

Initial creation