Bug 2527075 (CVE-2026-84475) - CVE-2026-84475 automation-controller: automation-controller-container: automation-controller: InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_t ...
Summary: CVE-2026-84475 automation-controller: automation-controller-container: automa...
Keywords:
Status: NEW
Alias: CVE-2026-84475
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-01 20:35 UTC by OSIDB Bzimport
Modified: 2026-09-23 18:30 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-01 20:35:17 UTC
A flaw was found in automation-controller (AWX). InventorySourceOptions.
source_vars (awx/main/models/inventory.py) is declared as a plain TextField
without a prevent_search() wrapper, unlike protected fields such as
CustomInventoryScript.script and Credential.inputs. django-ansible-base's
FieldLookupBackend permits __contains/__icontains/__startswith/__regex lookups
that traverse model joins without per-hop RBAC. Because the credential_types
list endpoint is readable by any authenticated user, an attacker holding zero
roles/organization/superuser/auditor privileges -- who is correctly denied on
the inventory_sources endpoints -- can query
credential_types?credentials__organization__inventories__inventory_sources__
source_vars__contains=<needle> (and the inventory_updates variant) and read
the result count as a boolean oracle (count>0 iff some tenant's source_vars
contains the needle). Using __regex the full plaintext is recovered
efficiently. source_vars is the documented location for inline dynamic-
inventory-plugin authentication (e.g. aws_access_key/aws_secret_key,
subscription_id/client_id/secret/tenant, username/password, token, api_key),
so the flaw discloses cross-tenant cloud-provider credentials to a zero-
privilege user. The field is defined on InventorySourceOptions and inherited
by InventorySource and InventoryUpdate. This is an instance of a broader class
in which unfiltered FieldLookupBackend joins on the globally-readable
credential_types list reach fields lacking prevent_search. Discovered
internally; verified live on AAP 2.7 / automation-controller 4.8.1.
    Upstream: github.com/ansible/awx (main/models/inventory.py) +
              django-ansible-base (FieldLookupBackend)


Note You need to log in before you can comment on or make changes to this bug.