PT-2026-97545 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84717

·

Published

2026-09-23

·

Updated

2026-09-26

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Ansible Automation Platform automation-controller (affected versions not specified)
Description An unauthenticated remote attacker can enumerate Job Template and Workflow Job Template IDs that have Bitbucket Data Center webhooks configured. This is possible because the Bitbucket Data Center webhook receiver skips HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity and authenticity) signature verification for diagnostics:ping events after the target template has been looked up. This results in a response discrepancy where the endpoint returns HTTP 200 if a template has a Bitbucket DC webhook configured and HTTP 403 otherwise, acting as an oracle for the attacker without requiring the webhook key secret.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84717
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible Automation Platform Automation-Controller