PT-2026-107393 · Red Hat · Red Hat Ansible Automation Platform 2+3

CVE-2026-103868

·

Published

2026-10-07

·

Updated

2026-10-07

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
A flaw was found in pulp-container when it authenticates to an upstream registry. Basic and bearer credentials from one remote are reused for later downloads in the same worker. A user who can sync a container remote, and can point that remote at a server they control, receives the username, password, or bearer token stored for a different remote, and can reuse that credential at the upstream registry. Content stored in Pulp is not changed, and the service is not stopped.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103868

Affected Products

Red Hat Ansible Automation Platform 2
Red Hat Satellite 6
Red Hat Update Infrastructure 4 For Cloud Providers
Red Hat Update Infrastructure 5