PT-2026-97509 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84499

·

Published

2026-09-23

·

Updated

2026-09-26

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description A flaw exists in the automation-controller where survey questions of type password, which are intended to be write-only and stored encrypted, can be exposed. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes the plaintext value in the minimum/maximum length validation error message returned in the HTTP response. An attacker with the delegated JobTemplate Admin role can exploit this by tightening the survey length constraint and triggering revalidation of a schedule or node created by a higher-privileged user to recover their plaintext password.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Generation of Error Message Containing Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84499
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible Automation Platform Automation-Controller