CVE-2026-11332

Aliases:GHSA-w8p5-mx5w-cpqjPYSEC-2026-3458DEBIAN-CVE-2026-11332openSUSE-SU-2026:11507-1openSUSE-SU-2026:11509-1openSUSE-SU-2026:11503-1RHSA-2026:57148RHSA-2026:57149RHSA-2026:66248RHSA-2026:67465RHSA-2026:67466RHSA-2026:67467
Awaiting Analysis
Published: 05 Jun 2026, 08:21
Last modified:15 Sept 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (cve.org)
EPSS Score
0.22% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

05 Jun 2026, 08:21
Published
Vulnerability first disclosed
15 Sept 2026, 12:04
Last Modified
Vulnerability information updated

Description

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.22% Percentile: 13%

Techniques & Countermeasures

  • CWE-88Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')

    The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Affected Systems

  • debianansible

    all | < 5.4.0-1 | < 5.4.0-1 | < 5.4.0-1

  • debianansible-core

    all | all | < 2.19.11-0+deb13u1 | < 2.21.1~rc1-1

  • PyPIansible-core

    < 2.16.19rc1 | ≥ 2.17.0b1, < 2.18.18rc1 | ≥ 2.19.0b1, < 2.19.11rc1 | ≥ 2.20.0b1, < 2.20.7rc1 | ≥ 2.21.0b1, < 2.21.1rc1

  • opensuseansible-lint&distro=openSUSE Tumbleweed

    < 26.8.0-1.1

  • opensusemolecule&distro=openSUSE Tumbleweed

    < 26.8.0-1.1

  • opensusepython-ansible-compat&distro=openSUSE Tumbleweed

    < 26.8.0-1.1

  • redhatansible-core

    < 1:2.16.16-2.el10_2.1 | < 1:2.14.18-3.el9_8.1 | < 0:2.16.3-4.el8_10 | < 1:2.16.14-1.el10_0.1 | < 1:2.14.18-1.el9_6.1 | < 1:2.14.14-1.el9_4.1

  • redhatansible-test

    < 1:2.16.16-2.el10_2.1 | < 1:2.14.18-3.el9_8.1 | < 0:2.16.3-4.el8_10 | < 1:2.16.14-1.el10_0.1 | < 1:2.14.18-1.el9_6.1 | < 1:2.14.14-1.el9_4.1

References (36)