Bug 2527117 (CVE-2026-84644)

Summary: CVE-2026-84644 automation-controller-container: automation-controller: automation-controller: server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the co ...
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dschmidt, jlanda, kshier, security-response-team, simaishi, stcannon, teagle, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Thycotic Secret Server external credential plugin passes a user-supplied server URL to its SDK without validating the scheme, host, or IP range, and the plugin backend is executed synchronously within the automation controller web process. Using the external credential test endpoint, a user who holds only the use role on such a credential can override the stored server URL with an arbitrary internal address, causing the control plane to issue requests to internal services. Although the response is a generic error, response timing reveals whether internal hosts and ports are reachable, enabling internal network reconnaissance and a blind request-forgery primitive from the control plane, and each request can hold a web worker, affecting availability.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-10-01   

Description OSIDB Bzimport 2026-09-01 21:49:22 UTC
A flaw was found in automation-controller (AWX). The external credential test
endpoints execute the credential plugin backend in-process in the controller web
service (awx/api/views/__init__.py CredentialExternalTest /
CredentialTypeExternalTest -> _call_backend_with_error_handling ->
plugin.backend()). CredentialExternalTest uses obj_permission_type='use' and
merges request-body 'inputs' over the stored credential inputs, so a user with
only the use role can override server_url. The Thycotic Secret Server plugin
(awx-plugins src/awx_plugins/credentials/tss.py tss_backend) passes server_url
verbatim into the delinea/thycotic SDK, which issues GET {server_url}/api/v1/
healthcheck and GET {server_url}/health and, on a healthy response, POST
{server_url}/oauth2/token, with no allow-list, scheme, IP-range, or DNS-rebind
check. Errors are wrapped as a bare SecretServerError (blind), but latency
differs by target state (refused ~0.5s vs filtered ~12s until the gateway 503s),
yielding a reliable timing oracle for scanning in-cluster services, the
Kubernetes API, link-local metadata (169.254.169.254), and localhost daemons
from the control-plane pod. This is the same root-cause class as the previously
reported HashiCorp Vault / Centrify / CyberArk CCP credential-plugin SSRFs;
Thycotic Secret Server is an additional sink. Discovered internally; verified
live on AAP 2.6/2.7 / automation-controller 4.8.1; still present on devel (both
awx and awx-plugins).
    Upstream: github.com/ansible/awx (awx/api/views/__init__.py
              CredentialExternalTest, CredentialTypeExternalTest,
              _call_backend_with_error_handling); github.com/ansible/awx-plugins
              (src/awx_plugins/credentials/tss.py tss_backend)

Comment 3 Jon Orris 2026-09-23 20:51:02 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 4 Jon Orris 2026-09-23 21:07:44 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114