PT-2026-97435 · Red Hat · Red Hat Ansible Automation Platform 2+5

·

CVE-2026-71458

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before Role-Based Access Control (RBAC) is applied. Because the 403 to 404 response shim only rewrites 403 responses, the path for a pk=0 miss returns a different 404 detail string. This difference between "Not found." and "No matches..." allows an attacker to determine if a named resource, such as an organization, credential, inventory, or host, exists anywhere on the platform, enabling cross-tenant internal hostname enumeration.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71458
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Red Hat Ansible Automation Platform 2
Red Hat Ansible Automation Platform 2.5 For Rhel 8
Red Hat Ansible Automation Platform 2.5 For Rhel 9
Red Hat Ansible Automation Platform 2.6
Red Hat Ansible Automation Platform 2.6 For Rhel 9
Red Hat Ansible Automation Platform 2.7