BlackTreeCVE IntelligenceOfficial source evidenceaccess.redhat.comVersioned article
Official source article · access.redhat.com
CVE-2026-84711 - Red Hat Customer Portal
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publisheraccess.redhat.com
Article IDNo stable ID in source URL
Verified snapshot26 Sept 2026, 14:36 UTC
Linked CVEs1
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-84711automation-controller: automation-controller: Project scm_branch/scm_refspec argument injection into git during project sync allows arbitrary file read on the sync host (control-plane ServiceAccount token, SECRET_KEY, and DB credentials on control-plane deployments) leading to full AAP and Kubernetes-namespace compromise
Source and provenance
Original title: CVE-2026-84711 - Red Hat Customer Portal. Captured 26 Sept 2026, 14:36 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗