Bug 2519720 (CVE-2026-76648)

Summary: CVE-2026-76648 automation-controller: automation-controller-container: AAP Controller: CopyAPIView.post() missing read authorization check enables Job Template secret recovery
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dschmidt, jlanda, kshier, security-response-team, simaishi, stcannon, teagle, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines 1001–1010) does not. POST only checks: can_access(model, 'add', create_kwargs_check) can_access(model, 'copy_related', obj) For JobTemplate, can_add (awx/awx/main/access.py:1465–1520) gates on inventory.use_role + project.use_role + execution_environment.read_role — resource-level roles that do not imply read on the source JT — and can_copy_related (1522–1534) checks only credentials.use_role. None of these imply the caller can read the source JT.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-09-06   

Description OSIDB Bzimport 2026-08-19 15:40:58 UTC
A flaw was found in the Ansible Automation Platform Controller.
    The CopyAPIView.post() method does not verify that the
    requesting user has read access to the source object before
    performing the copy operation, while the corresponding GET
    handler does enforce this check. A user with Use roles on a
    shared project and inventory can copy any Job Template built
    on those resources — including Job Templates they cannot read
    — and become Admin of the clone. The clone contains the source
    Job Template's plaintext host_config_key and extra_vars fields,
    which frequently contain secrets. The recovered host_config_key
    can be used to authenticate against the original Job Template's
    provisioning callback endpoint.