CVE-2026-84713

6.5

Red Hat · Ansible Automation Platform

An authorization bypass in the Red Hat Ansible Automation Platform notification subsystem allows authenticated users to recover sensitive recipient credentials via a boolean count-oracle attack.

Executive summary

A critical information disclosure vulnerability in the Red Hat Ansible Automation Platform notification subsystem allows authenticated users to exfiltrate sensitive credentials across tenant boundaries.

Vulnerability

The flaw resides in the automation-controller notification subsystem where the API filter backend fails to enforce per-hop authorization when traversing object relations. Any authenticated user can leverage a relational filter as a boolean count-oracle to extract sensitive recipient data, such as PagerDuty service keys and webhook bearer tokens, from other tenants.

Business impact

Successful exploitation results in the unauthorized disclosure of highly sensitive external service credentials, potentially granting an attacker access to third-party infrastructure integrated with the automation platform. While the CVSS score of 6.5 reflects a medium severity, the ability to bypass tenant isolation and exfiltrate secrets across organizational boundaries presents a significant risk to the overall security posture and data confidentiality of the enterprise.

Remediation

Immediate Action: Upgrade to the latest version of Red Hat Ansible Automation Platform, ensuring the installation includes the fixes provided in RHSA-2026:71177 or later.

Proactive Monitoring: Review API access logs for anomalous, high-frequency relational filter queries that may indicate an attempt to perform character by character data exfiltration.

Compensating Controls: Implement strict API gateway controls and limit the scope of user permissions where possible to minimize the potential impact of authenticated users traversing unauthorized object relationships.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given that this vulnerability allows for the cross-tenant exfiltration of critical service credentials, organizations should prioritize the application of the vendor-supplied patch. Administrators must verify their current deployment version and apply the updates identified in the Red Hat security advisory to prevent unauthorized access to sensitive integration secrets.

More Red Hat CVEs all →

History

  1. Analyst report written

Sources