PT-2026-97509 · Red Hat · Ansible Automation Platform Automation-Controller
CVE-2026-84499
·
Published
2026-09-23
·
Updated
2026-09-26
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description
A flaw exists in the automation-controller where survey questions of type password, which are intended to be write-only and stored encrypted, can be exposed. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes the plaintext value in the minimum/maximum length validation error message returned in the HTTP response. An attacker with the delegated JobTemplate Admin role can exploit this by tightening the survey length constraint and triggering revalidation of a schedule or node created by a higher-privileged user to recover their plaintext password.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Generation of Error Message Containing Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform Automation-Controller