Bug 2527140 (CVE-2026-84686)

Summary: CVE-2026-84686 automation-controller: automation-controller-container: automation-controller: notification template password fields can be decrypted by a notification-template administrator by replaying encrypted values across subfields, exposing plai ...
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: dschmidt, jlanda, kshier, security-response-team, simaishi, stcannon, teagle, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Notification template password fields are encrypted with a key derived from the secret key, the object primary key, and the field name, but not the subfield name, and the API returns the full ciphertext of a password subfield after the notification type is changed to one that does not define that subfield. A user with administrative access to a single notification template, but without any wider privilege, can switch the template type to reveal the stored ciphertext, replant that ciphertext into a webhook password field pointing at a server they control, and trigger a test notification. The controller decrypts the replayed ciphertext to the original plaintext and sends it to the attacker's server in an HTTP Basic authorization header, allowing recovery of Slack, PagerDuty, Twilio, AWS SNS, and Grafana credentials the administrator was only permitted to use, not read.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-10-01   

Description OSIDB Bzimport 2026-09-01 22:47:56 UTC
A flaw was found in automation-controller (AWX). Four compounding issues let a
holder of object-level NotificationTemplate admin recover the plaintext of
notification credentials for fixed-endpoint backends:
(1) NotificationTemplate.display_notification_configuration() (awx/main/models/
notifications.py) masks only password subfields of the CURRENT notification type,
so after a type change the previous type's password subfield is returned with its
full Fernet ciphertext; (2) NotificationTemplateSerializer.validate() (awx/api/
serializers.py) returns early when notification_configuration is absent from the
request body, allowing a type-only change that keeps the stale ciphertext; (3)
NotificationTemplate.save() skips re-encryption of any value beginning with
"$encrypted$" and the serializer's forward sentinel tests exact equality with
"$encrypted$", so a full ciphertext replanted into a different password subfield
is stored verbatim; (4) get_encryption_key() (awx/main/utils/encryption.py)
derives the Fernet key from the secret key, primary key, and field name only --
not the subfield -- so a ciphertext produced for one subfield decrypts as any
other subfield of the same object. Chaining these, an attacker switches the
template type to leak the ciphertext, replants it into a webhook password with an
attacker-controlled URL, and triggers /test/; the controller decrypts and sends
the plaintext to the attacker in an HTTP Basic auth header. Verified live on AAP
2.7 / automation-controller 4.8.1; still present on devel.
    Upstream: github.com/ansible/awx (awx/main/models/notifications.py;
              awx/api/serializers.py; awx/main/utils/encryption.py;
              awx/main/notifications/webhook_backend.py)

Comment 2 Jon Orris 2026-09-23 20:51:12 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 3 Jon Orris 2026-09-23 21:07:51 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114