Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2016-9587

38
FAUCET Score

CVE-2016-9587 is an improper input validation vulnerability affecting Ansible versions prior to 2.1.4 and 2.2.1, including Red Hat Ansible and OpenStack distributions. An attacker controlling a client system managed by Ansible could exploit this flaw by sending malicious data (facts) to the Ansible server, leading to arbitrary code execution with server privileges. This high-severity vulnerability (CVSS 8.1) has a high impact on confidentiality, integrity, and availability, with a network attack vector and high attack complexity. While not listed on CISA's KEV catalog, an exploit (EDB-41013) exists, and it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.1.4CPE matchmatch criteria
cpe:2.3:a:redhat:ansible:*:*:*:*:*:*:*:*
< 2.2.1CPE matchmatch criteria
cpe:2.3:a:ansible:ansible:*:*:*:*:*:*:*:*
11CPE matchmatch criteria
cpe:2.3:a:redhat:openstack:11:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.6MEDIUM

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.7
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
17.65%
Probability of exploitation in next 30 days
EPSS Percentile
96.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-41013 · Jan 9, 2017
This CVE's current EPSS score of 0.1765 is in the 83rd percentile among its peer group of 8,913 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (19)

pippatch availablevia ghsa
Product: ansibleFixed in: 2.1.4.0
pippatch availablevia ghsa
Product: ansibleFixed in: 2.2.1.0
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.4Fixed in: ansible-0:2.2.1.0-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.1 for RHEL 7Fixed in: ansible-0:2.2.1.0-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.1 for RHEL 7Fixed in: gdeploy-0:2.0.1-8.el7rhgs
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Gluster Storage 3.1 for RHEL 7Fixed in: python-passlib-0:1.6.5-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.2Fixed in: ansible-0:2.2.1.0-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.2Fixed in: openshift-ansible-0:3.2.53-1.git.0.2fefc17.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.3Fixed in: ansible-0:2.2.1.0-2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.3Fixed in: openshift-ansible-0:3.3.67-1.git.0.7c5da0c.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.4Fixed in: openshift-ansible-0:3.4.67-1.git.0.14a0b4d.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 10.0 (Newton)Fixed in: ansible-0:2.2.1.0-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage Console 2 for Red Hat Enteprise Linux 7Fixed in: ansible-0:2.2.1.0-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage Console 2 for Red Hat Enteprise Linux 7Fixed in: ceph-ansible-0:2.1.9-1.el7scon
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage Console 2 for Red Hat Enteprise Linux 7Fixed in: ceph-installer-0:1.2.2-1.el7scon
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Storage Console 2 for Red Hat Enteprise Linux 7Fixed in: python-passlib-0:1.6.5-1.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization Engine 4.1Fixed in: ansible-0:2.3.0.0-4.el7
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 11 (Ocata)Fixed in: ansible
redhatend of lifevia redhat_api
Product: Red Hat Quickstart Cloud Installer 1Fixed in: ansible

Vendor Advisories (2)

pipGHSA-m956-frf4-m2wrcritical

Ansible is vulnerable to an improper input validation in Ansible's handling of data sent from client systems

Oct 10, 2018
redhatCVE-2016-9587Important

Ansible: Compromised remote hosts can lead to running commands on the Ansible controller

Jan 9, 2017

References

rhn.redhat.com / errata/RHSA-2017-0195.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2017-0260.html
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0448
Third Party Advisory
access.redhat.com / errata/RHSA-2017:0515
Third Party Advisory
access.redhat.com / errata/RHSA-2017:1685
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
security.gentoo.org / glsa/201701-77
Third Party Advisory
exploit-db.com / exploits/41013
ExploitThird Party AdvisoryVDB Entry
securityfocus.com / bid/95352
Third Party AdvisoryVDB Entry