PT-2026-97436 · Red Hat · Red Hat Ansible Automation Platform 2+5

·

CVE-2026-71459

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The JobJobEventsChildrenSummary view lacks a defined model or parent model, causing the ModelAccessPermission.check get permissions() function to return True for any authenticated user. Because the view utilizes get object or 404(Job, pk) without implementing Django Rest Framework (DRF) object-level permission checks, an authenticated user with zero privileges can access the event tree structure and the event processing finished status. Additionally, this allows for the enumeration of Job IDs across the platform using a 200/404 oracle, where the server response indicates whether a specific ID exists. This occurs while the sibling endpoint '/jobs/{id}/job events/' correctly enforces permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71459
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Red Hat Ansible Automation Platform 2
Red Hat Ansible Automation Platform 2.5 For Rhel 8
Red Hat Ansible Automation Platform 2.5 For Rhel 9
Red Hat Ansible Automation Platform 2.6
Red Hat Ansible Automation Platform 2.6 For Rhel 9
Red Hat Ansible Automation Platform 2.7