Junglewise Threat Intelligence

CVE-2024-9902: PYSEC-2026-1121 - ansible-core Incorrect Authorization vulnerability

CVE-2024-9902 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: ansible-core (PyPI). Vendors: Ansible, PyPI.

Executive brief

Ansible's user module, which is used to manage system user accounts and SSH keys across managed systems, contains an authorization flaw that allows unprivileged users to create or modify files and take ownership of them when a privileged user runs the module. If an unprivileged user can traverse directories, they can retain permanent control over files created through this vulnerability, potentially compromising system integrity and data security.

Technical details

The vulnerability exists in ansible-core's user module, which improperly validates authorization when handling SSH key generation and file operations. An unprivileged user can exploit a directory traversal condition to cause a privileged user executing the user module against the unprivileged user's home directory to silently create, replace, or take ownership of arbitrary files on system paths. The flaw involves inadequate checks on SSH key file operations (ssh-keygen, chown, chmod), particularly when handling existing symlinked SSH public key files. Attack vector is local with low privileges required; exploitation typically requires the unprivileged user to have directory traversal permissions and a privileged Ansible user to execute the vulnerable module. Fixes are available in ansible-core versions 2.14.18+, 2.15.13+, 2.16.13+, 2.17.6+, and 2.18.0rc2+.

Affected products

  • Ansible ansible-core All versions before 2.14.18; 2.15.0 before 2.15.13; 2.16.0 before 2.16.13; 2.17.0 before 2.17.6; 2.18.0 before 2.18.0rc2

Timeline

  • 2024-11-06: disclosed
  • 2024-10-28: patched: Fixes committed to stable branches

References

Related threats