PT-2026-97545 · Red Hat · Ansible Automation Platform Automation-Controller
CVE-2026-84717
·
Published
2026-09-23
·
Updated
2026-09-26
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible Automation Platform automation-controller (affected versions not specified)
Description
An unauthenticated remote attacker can enumerate Job Template and Workflow Job Template IDs that have Bitbucket Data Center webhooks configured. This is possible because the Bitbucket Data Center webhook receiver skips HMAC (Hash-based Message Authentication Code, a mechanism for verifying data integrity and authenticity) signature verification for
diagnostics:ping events after the target template has been looked up. This results in a response discrepancy where the endpoint returns HTTP 200 if a template has a Bitbucket DC webhook configured and HTTP 403 otherwise, acting as an oracle for the attacker without requiring the webhook key secret.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform Automation-Controller