Vulnerability scans or security assessments may identify a high-severity vulnerability (CVE-2026-27135) related to the libnghttp2 package in Automation Engine version 24.4.4 or lower. This vulnerability stems from an outdated version of the library bundled within the install-operator image. This article provides the remediation steps required to address this security finding.
Product: CA Automic Workload Automation 24.4.4
Component: install-operator image
Automation Engine version 24.4.4.1 utilizes a version of the libnghttp2 library susceptible to CVE-2026-27135 (an HTTP/2 assertion failure that enables remote Denial of Service).
This vulnerability is resolved in Automation Engine version 24.4.5 and higher. Version 24.4.5 includes the updated, non-vulnerable libnghttp2 package (version 1.68.0-3.el10_2.1.x86_64).