Back

advisor-backend: Unsafe YAML deserialization of associate-editable Task playbook (yaml.Loader)

Published Sep 2, 2026

Description

A flaw was found in advisor-backend. Multiple code paths within the application deserialize YAML (YAML Ain't Markup Language) with an unsafe full Loader, which can instantiate arbitrary Python objects via YAML tags. An unauthenticated remote attacker can exploit this by submitting specially crafted YAML input, leading to remote code execution (RCE) within the `advisor-backend` pod. This compromise could allow access to shared database credentials and impact all tenants.

Affected products

Remediation

Red Hat statement

This Critical vulnerability in Red Hat Insights advisor-backend enables unauthenticated remote code execution. An attacker can exploit an unsafe YAML deserialization flaw, chained with an unauthenticated content import path, to execute arbitrary code within the multi-tenant advisor-backend pod. This allows for compromise of shared database credentials and tenant data, justifying the Critical impact due to the unauthenticated RCE.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Published Sep 2, 2026

CISA Vulnrichment

No data

NVD

No data

Red Hat

Severity Critical
Public date Sep 2, 2026
Bugzilla 2519653

ENISA EUVD

No data

GitHub

No data