{"id":"CVE-2026-87874","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-87874","summary":"A flaw was found in the memcached cache plugin of the community.general Ansible\ncollection. Although its documentation states that records are stored in JSON\nformat, the plugin performs…","details":"A flaw was found in the memcached cache plugin of the community.general Ansible\ncollection. Although its documentation states that records are stored in JSON\nformat, the plugin performs no explicit serialization and relies on\npython-memcached, which pickles values on write and unpickles them on read.\nBecause memcached is unauthenticated and cache keys are predictable, an attacker\nable to reach a network-exposed or shared memcached instance can write a crafted\npickle payload that is deserialized and executed on the Ansible controller when\nthe poisoned fact cache is next read, leading to remote code execution.","published":"2026-09-09T16:06:22.995Z","modified":"2026-09-09T16:59:14.348Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-87874"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530995"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T16:59:14.348Z"}}