Bug 2506053 (CVE-2026-16544) - CVE-2026-16544 awx: websocket EventConsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure
Summary: CVE-2026-16544 awx: websocket EventConsumer missing authorization for invento...
Keywords:
Status: NEW
Alias: CVE-2026-16544
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-22 10:04 UTC by OSIDB Bzimport
Modified: 2026-07-22 11:11 UTC (History)
7 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-22 10:04:06 UTC
A flaw was found in the AWX websocket event consumer. The consumer_access() function in awx/main/access.py maps RBAC access classes for only three event groups (job_events, workflow_events, ad_hoc_command_events). When EventConsumer.receive_json() in awx/main/consumers.py processes a subscription request for the three unmapped groups (inventory_update_events, project_update_events, system_job_events), consumer_access() returns None, causing the RBAC authorization check to be skipped entirely. The user is unconditionally subscribed to the channel. As a result, any authenticated user - regardless of role or organization membership - can subscribe to these websocket groups for any object ID and receive real-time stdout output and event_data from inventory syncs, project updates, and system jobs belonging to other organizations. This is an incomplete remediation of CVE-2020-10698, which established the RBAC mechanism but only mapped three of the six subscribable event groups. Object IDs are globally sequential UnifiedJob IDs and are trivially enumerable. Stdout data on the websocket path is not redacted (redaction exists only in REST serializers), and project update stdout may contain SCM basic-auth credentials. Verified on AWX 24.6.1; same code path confirmed on devel branch.


Note You need to log in before you can comment on or make changes to this bug.