PT-2026-97507 · Red Hat · Ansible Automation Platform Automation-Controller
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description
A flaw exists where the
host config key (provisioning-callback secret) is exposed to users with only the view jobtemplate read-level permission via the job template API and the activity stream. Additionally, when the controller is deployed behind the AAP gateway with an empty proxy allow-list, the provisioning callback endpoint trusts the client-supplied X-Forwarded-For header to identify the calling host. A minimally privileged or unauthenticated remote attacker can use the leaked secret and spoof the X-Forwarded-For header to match a host in the job template's inventory, allowing them to launch the job template against arbitrary managed hosts using the template's credentials. This leads to privilege escalation and remote code execution on the managed hosts.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform Automation-Controller