Bug 2519720 (CVE-2026-76648) - CVE-2026-76648 automation-controller: automation-controller-container: AAP Controller: CopyAPIView.post() missing read authorization check enables Job Template secret recovery
Summary: CVE-2026-76648 automation-controller: automation-controller-container: AAP Co...
Keywords:
Status: NEW
Alias: CVE-2026-76648
Deadline: 2026-09-06
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-19 15:40 UTC by OSIDB Bzimport
Modified: 2026-09-23 17:46 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-19 15:40:58 UTC
A flaw was found in the Ansible Automation Platform Controller.
    The CopyAPIView.post() method does not verify that the
    requesting user has read access to the source object before
    performing the copy operation, while the corresponding GET
    handler does enforce this check. A user with Use roles on a
    shared project and inventory can copy any Job Template built
    on those resources — including Job Templates they cannot read
    — and become Admin of the clone. The clone contains the source
    Job Template's plaintext host_config_key and extra_vars fields,
    which frequently contain secrets. The recovered host_config_key
    can be used to authenticate against the original Job Template's
    provisioning callback endpoint.


Note You need to log in before you can comment on or make changes to this bug.