Bug 2527196 (CVE-2026-84712)

Summary: CVE-2026-84712 automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: dschmidt, jlanda, kshier, security-response-team, simaishi, stcannon, teagle, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the full instance inventory (node hostnames, node types, UUIDs, heartbeats, capacities, and exact versions), all instance-group names and membership, the deployment install UUID, and the active control node. A remote, unauthenticated attacker can use this to map the control plane and fingerprint software versions for targeted attacks. This flaw affects confidentiality only; it does not expose secrets, credentials, or tenant data.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-10-01   

Description OSIDB Bzimport 2026-09-02 00:49:29 UTC
A missing-authorization information-disclosure flaw was found in the
  automation-controller API. The endpoint GET /api/v2/ping/ (also reachable as
  /api/controller/v2/ping/) is served by ApiV2PingView with
  permission_classes=(AllowAny,) and authentication_classes=(), making it fully
  anonymous by design so that the installer and load-balancer health probes can
  reach it. Beyond the intended liveness fields (high-availability flag and
  product version), the endpoint's GET handler enumerates every automation-mesh
  Instance (excluding hop nodes) and every InstanceGroup without any query
  scoping, and serializes them into the anonymous response. As a result, an
  unauthenticated remote attacker who can reach the Controller API learns the
  complete mesh inventory — each node's hostname, node type
  (control/hybrid/execution), UUID, last heartbeat, capacity, and exact AWX
  version — together with every instance group's name, capacity, and member
  hostnames, plus the deployment's install UUID and the active control node
  identifier. This is data that the authenticated /instances/ and
  /instance_groups/ endpoints protect behind authentication and role-based
  access control. Exposing it pre-authentication provides an attacker with
  detailed internal reconnaissance: it maps the control plane, identifies the
  highest-value nodes, and reveals exact software versions for targeted exploit
  selection. No credentials, job data, tenant data, or configuration secrets are
  exposed, so the confidentiality impact is limited and there is no impact on
  integrity or availability. The issue is that the endpoint over-serializes
  RBAC-gated topology into a response that is intentionally unauthenticated; the
  unauthenticated liveness check itself is expected behavior.

Comment 3 Jon Orris 2026-09-23 20:51:27 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 4 Jon Orris 2026-09-23 21:08:03 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114