6.5

CVE-2026-84713

Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracle

A flaw was found in the automation-controller notification
                  subsystem. Although NotificationTemplate.notification_
                  configuration is protected from API filtering, its recipient
                  value is copied in clear text into the unprotected
                  Notification.recipients field on every send. Because the
                  credential-types endpoint is listable by any authenticated
                  user and the API filter backend traverses object relations
                  without per-hop authorization, a user with no privileges can
                  use a relational filter as a boolean count-oracle to recover,
                  character by character and across organizations, the secret
                  recipient values of other tenants' notifications — including
                  PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook
                  bearer-token URLs. This flaw affects confidentiality.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2.7
Default Statusaffected
Version 1789580684
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat Ansible Automation Platform 2
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.213
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://access.redhat.com/security/cve/CVE-2026-84713
https://bugzilla.redhat.com/show_bug.cgi?id=2527197
https://access.redhat.com/errata/RHSA-2026:71177