CVE-2026-55074 Details
Description
Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and ran mkdir -p and mv there as root on the host. Those commands follow symbolic links, and the path was operated on outside the jail, so a symlink existing inside the jail was followed by the host-side, root-privileged mv. A party controlling content inside a managed jail (the jail's root, or any process able to create a symlink in a directory an Ansible task later writes to) can therefore cause an arbitrary root-owned write on the host, outside the jail — a full jail escape. Arbitrary root-owned host writes are readily escalated to host compromise (e.g. cron, rc.d, authorized_keys). Preconditions for this vulnerability are that the operator runs a copy/template/fetch-style task (anything using put_file) against the jail, and the attacker can place a symlink inside the jail at or above the task's destination before the transfer runs. This issue has been fixed in version 2.0.0.
A vulnerability exists in the Ansible FreeBSD Jail Connection Plugin, specifically in versions through 1.3.0. The issue arises in the 'put_file' function of the 'jailexec' connection plugin, which improperly handles file transfers by resolving destination paths on the jail host instead of within the jail's confined environment. This flaw allows a user with control over a managed jail to create a symlink that redirects a privileged file operation onto the host, effectively escaping the jail's restrictions. The vulnerability can be exploited by placing a symlink inside the jail that points to a location on the host where an Ansible task will write a file, thereby achieving unauthorized write access as root on the host system.
Upgrade to version 2.0.0 or later of the Ansible FreeBSD Jail Connection Plugin. After upgrading, no inventory changes are needed for the default 'ansible_jail_user' configuration, but jails should be treated as untrusted until verified that the update was applied.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 21, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Ansible FreeBSD Jail Connection Plugin | < 2.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 21, 2026 | New CVE Received | [email protected] |
Volerion