← All Advisories

CVE-2026-11332

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-11332

Key Details

CVECVE-2026-11332
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-10-08
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-88 (Improper Neutralization of Argument Delimiters in a Command ('Argument Injection'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Ansible Automation Platform 2.6
Red HatRed Hat Ansible Automation Platform 2.7
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Enterprise Linux 9.4 Update Services for SAP Solutions
Red HatRed Hat Enterprise Linux 9.6 Extended Update Support
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Discovery 2
Red HatRed Hat Satellite 6.17 for RHEL 9
Red HatRed Hat Satellite 6.18 for RHEL 9
Red HatRed Hat Satellite 6.19 for RHEL 9
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 10
Red HatRed Hat Ansible Automation Platform 2.7 for RHEL 10
Red HatRed Hat Ansible Automation Platform 2.7 for RHEL 9
Red HatRed Hat Ansible Automation Platform 2.5
Red HatMigration Toolkit for Applications 8
Red HatMigration Toolkit for Virtualization
Red HatRed Hat Ansible Automation Platform Ansible Core 2
Red HatSelf-service automation portal 2
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-11332
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-11332