Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4110 articles · 197511 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-11332EXPLOITEDPATCHED
red hat · ansible-core

Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution

Description

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

Affected Products

VendorProductVersions
red hatansible-core—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
pipansible-coreGHSA85%
red hatansible automationcert_advisory90%

References

  • https://access.redhat.com/errata/RHSA-2026:42078(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:42079(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:42080(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:46836(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50340(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50344(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50357(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:50479(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:57148(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/errata/RHSA-2026:57149(vendor-advisory, x_refsource_REDHAT)
  • https://access.redhat.com/security/cve/CVE-2026-11332(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2485379(issue-tracking, x_refsource_REDHAT)
  • https://github.com/ansible/ansible

Related News (5 articles)

Tier B
BSI Advisories20d ago
[NEU] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung
→ No new info (linked only)
Tier B
BSI Advisories78d ago
[UPDATE] [mittel] Ansible: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode und Offenlegung von Daten
→ No new info (linked only)
Tier B
BSI Advisories78d ago
[UPDATE] [mittel] Ansible: Schwachstelle ermöglicht Ausführen von beliebigem Programmcode mit den Rechten des Dienstes
→ No new info (linked only)
Tier A
Microsoft MSRC79d ago
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution
→ No new info (linked only)
Tier C
VulDB81d ago
CVE-2026-11332 | Red Hat Ansible Automation Platform 2 ansible-core meta/requirements.yml src argument injection
→ No new info (linked only)
CVSS 3.17.8 NONE
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
ansible-core@2.16.19rc1ansible-core@2.18.18rc1ansible-core@2.19.11rc1ansible-core@2.20.7rc1ansible-core@2.21.1rc1
CWECWE-88
PublishedJun 5, 2026
Last enriched78d agov3
Trending Score3
Source articles5
Independent3
Info Completeness8/14
Missing: versions, epss, kev, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-78367EXP
Rpm: rpmbuild gettarspec() crafted tar member name → macro injection
Trending: 59
NONECVE-2026-78465EXP
Gimp: integer overflow in pcx loader (planes=4) leads to heap overflow on 32-bit
Trending: 59
HIGHCVE-2026-79655EXP
Sos: sos: path traversal in sos clean tar extraction via unvalidated symlink/hardlink targets leads to arbitrary file write
Trending: 56
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 54
CRITICALCVE-2026-19685EXP
Networkmanager: networkmanager: 802-1x ca-path and phase2-ca-path bypass private_user restriction, allowing wpa-enterprise server validation bypass (incomplete fix for cve-2025-9615)
Trending: 54

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 5, 2026
Discovered by ZDM
Jun 5, 2026
Updated: severity
Jun 5, 2026
Updated: severity, exploitAvailable, activelyExploited
Jun 8, 2026
Actively Exploited
Aug 20, 2026
Exploit Available
Aug 20, 2026
Patch Available
Aug 20, 2026

Version History

v3
Last enriched 78d ago
v3Tier B78d ago

Updated severity to HIGH and marked the vulnerability as actively exploited with an exploit available.

severityexploitAvailableactivelyExploited
via BSI Advisories
v2Tier C81d ago

Updated severity to CRITICAL and corrected exploit availability to false.

severity
via VulDB
v181d ago

Initial creation