← All Advisories

CVE-2026-89091

Last refreshed2026-10-09

Status: UPDATED  |  Advisory ID: CVE-2026-89091

Key Details

CVECVE-2026-89091
CVSS Score / Version8.8 (High) / CVSS v3.1
Updated2026-10-09
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is required; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productssee table below
Classified asCWE-59 (Improper Link Resolution Before File Access ('Link Following'))

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Update Infrastructure 5
Red HatRed Hat OpenShift Container Platform 4
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Satellite 6
Red HatRed Hat Discovery 2
Red HatRed Hat Ansible Automation Platform Ansible Core 2
Red HatSelf-service automation portal 2
Red HatRed Hat OpenStack Platform 17.1
Red HatRed Hat Advanced Cluster Management for Kubernetes 2
SubsystemsOT Supporting Infrastructure
SectorsMultiple

What to Know

A flaw was found in ansible-core. When installing a collection with

`ansible-galaxy collection install`, the archive extractor validates member

paths using lexical path normalisation (os.path.abspath) instead of resolving

symbolic links (os.path.realpath), and it performs no containment check on

symlink-typed directory members before creating them. A crafted collection

tarball can chain symlink directory entries so that a subsequent file member is

written outside the intended destination directory. This allows an attacker who

can get a victim to install a malicious collection to overwrite arbitrary files

with the privileges of the user running ansible-galaxy, leading to code

execution on the control node. This is a bypass of the fix for CVE-2020-10691. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-89091
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-89091