PT-2026-97503 · Awx · Awx

CVE-2026-76648

·

Published

2026-09-23

·

Updated

2026-09-26

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AWX (affected versions not specified)
Description In the CopyAPIView located in awx/awx/api/generics.py, the permission classes is set to (IsAuthenticated,), which prevents the Django REST Framework's get object() from performing object-level Role-Based Access Control (RBAC). While the get() handler includes a guard using request.user.can access(obj. class , 'read', obj), the post() handler does not. The post() method only verifies can access(model, 'add', create kwargs check) and can access(model, 'copy related', obj). For JobTemplate, the can add() function in awx/awx/main/access.py checks for resource-level roles related to inventory, project, and execution environment, and can copy related() only checks credentials.use role. None of these checks ensure that the caller has read permissions for the source JobTemplate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76648

Affected Products

Awx