Bug 2527140 (CVE-2026-84686)
| Summary: | CVE-2026-84686 automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plai ... | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | dschmidt, jlanda, kshier, security-response-team, simaishi, stcannon, teagle, yguenane |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. Notification template password fields are encrypted with a key
derived from the secret key, the object primary key, and the field name, but not
the subfield name, and the API returns the full ciphertext of a password subfield
after the notification type is changed to one that does not define that subfield.
A user with administrative access to a single notification template, but without
any wider privilege, can switch the template type to reveal the stored
ciphertext, replant that ciphertext into a webhook password field pointing at a
server they control, and trigger a test notification. The controller decrypts the
replayed ciphertext to the original plaintext and sends it to the attacker's
server in an HTTP Basic authorization header, allowing recovery of Slack,
PagerDuty, Twilio, AWS SNS, and Grafana credentials the administrator was only
permitted to use, not read.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2026-10-01 | ||
This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.6 for RHEL 10 Red Hat Ansible Automation Platform 2.6 for RHEL 9 Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113 This issue has been addressed in the following products: Red Hat Ansible Automation Platform 2.5 for RHEL 9 Red Hat Ansible Automation Platform 2.5 for RHEL 8 Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114 |
A flaw was found in automation-controller (AWX). Four compounding issues let a holder of object-level NotificationTemplate admin recover the plaintext of notification credentials for fixed-endpoint backends: (1) NotificationTemplate.display_notification_configuration() (awx/main/models/ notifications.py) masks only password subfields of the CURRENT notification type, so after a type change the previous type's password subfield is returned with its full Fernet ciphertext; (2) NotificationTemplateSerializer.validate() (awx/api/ serializers.py) returns early when notification_configuration is absent from the request body, allowing a type-only change that keeps the stale ciphertext; (3) NotificationTemplate.save() skips re-encryption of any value beginning with "$encrypted$" and the serializer's forward sentinel tests exact equality with "$encrypted$", so a full ciphertext replanted into a different password subfield is stored verbatim; (4) get_encryption_key() (awx/main/utils/encryption.py) derives the Fernet key from the secret key, primary key, and field name only -- not the subfield -- so a ciphertext produced for one subfield decrypts as any other subfield of the same object. Chaining these, an attacker switches the template type to leak the ciphertext, replants it into a webhook password with an attacker-controlled URL, and triggers /test/; the controller decrypts and sends the plaintext to the attacker in an HTTP Basic auth header. Verified live on AAP 2.7 / automation-controller 4.8.1; still present on devel. Upstream: github.com/ansible/awx (awx/main/models/notifications.py; awx/api/serializers.py; awx/main/utils/encryption.py; awx/main/notifications/webhook_backend.py)