advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)
Published Sep 2, 2026
No CVSS score
Description
A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants.
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This Critical vulnerability in Red Hat Insights advisor-backend enables unauthenticated remote code execution. An attacker can exploit an unsafe YAML deserialization flaw, chained with an unauthenticated content import path, to execute arbitrary code within the multi-tenant advisor-backend pod. This allows for compromise of shared database credentials and tenant data, justifying the Critical impact due to the unauthenticated RCE.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
References (4)
- https://access.redhat.com/security/cve/CVE-2026-76595 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2519653 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-76595
- https://www.cve.org/CVERecord?id=CVE-2026-76595
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-76595 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2519653 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-76595 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-76595 |
Change history (0)
No recorded changes yet.
CISA Vulnrichment
No data
NVD
No data
ENISA EUVD
No data
GitHub
No data