PT-2026-97503 · Awx · Awx
CVE-2026-76648
·
Published
2026-09-23
·
Updated
2026-09-26
CVSS v3.1
8.5
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AWX (affected versions not specified)
Description
In the
CopyAPIView located in awx/awx/api/generics.py, the permission classes is set to (IsAuthenticated,), which prevents the Django REST Framework's get object() from performing object-level Role-Based Access Control (RBAC). While the get() handler includes a guard using request.user.can access(obj. class , 'read', obj), the post() handler does not. The post() method only verifies can access(model, 'add', create kwargs check) and can access(model, 'copy related', obj). For JobTemplate, the can add() function in awx/awx/main/access.py checks for resource-level roles related to inventory, project, and execution environment, and can copy related() only checks credentials.use role. None of these checks ensure that the caller has read permissions for the source JobTemplate.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Awx