Bug 2527117 (CVE-2026-84644) - CVE-2026-84644 automation-controller-container: automation-controller: automation-controller: server-side request forgery via the Thycotic Secret Server external credential plugin test endpoint (caller-controlled server_url, backend executed in the co ...
Summary: CVE-2026-84644 automation-controller-container: automation-controller: automa...
Keywords:
Status: NEW
Alias: CVE-2026-84644
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-01 21:49 UTC by OSIDB Bzimport
Modified: 2026-09-23 21:07 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:71113 0 None None None 2026-09-23 20:51:03 UTC
Red Hat Product Errata RHSA-2026:71114 0 None None None 2026-09-23 21:07:45 UTC

Description OSIDB Bzimport 2026-09-01 21:49:22 UTC
A flaw was found in automation-controller (AWX). The external credential test
endpoints execute the credential plugin backend in-process in the controller web
service (awx/api/views/__init__.py CredentialExternalTest /
CredentialTypeExternalTest -> _call_backend_with_error_handling ->
plugin.backend()). CredentialExternalTest uses obj_permission_type='use' and
merges request-body 'inputs' over the stored credential inputs, so a user with
only the use role can override server_url. The Thycotic Secret Server plugin
(awx-plugins src/awx_plugins/credentials/tss.py tss_backend) passes server_url
verbatim into the delinea/thycotic SDK, which issues GET {server_url}/api/v1/
healthcheck and GET {server_url}/health and, on a healthy response, POST
{server_url}/oauth2/token, with no allow-list, scheme, IP-range, or DNS-rebind
check. Errors are wrapped as a bare SecretServerError (blind), but latency
differs by target state (refused ~0.5s vs filtered ~12s until the gateway 503s),
yielding a reliable timing oracle for scanning in-cluster services, the
Kubernetes API, link-local metadata (169.254.169.254), and localhost daemons
from the control-plane pod. This is the same root-cause class as the previously
reported HashiCorp Vault / Centrify / CyberArk CCP credential-plugin SSRFs;
Thycotic Secret Server is an additional sink. Discovered internally; verified
live on AAP 2.6/2.7 / automation-controller 4.8.1; still present on devel (both
awx and awx-plugins).
    Upstream: github.com/ansible/awx (awx/api/views/__init__.py
              CredentialExternalTest, CredentialTypeExternalTest,
              _call_backend_with_error_handling); github.com/ansible/awx-plugins
              (src/awx_plugins/credentials/tss.py tss_backend)

Comment 3 Jon Orris 2026-09-23 20:51:02 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 10
  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:71113 https://access.redhat.com/errata/RHSA-2026:71113

Comment 4 Jon Orris 2026-09-23 21:07:44 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:71114 https://access.redhat.com/errata/RHSA-2026:71114


Note You need to log in before you can comment on or make changes to this bug.