CVE-2026-103869
- EPSS 0.23%
- Veröffentlicht 07.10.2026 05:46:15
- Zuletzt bearbeitet 07.10.2026 19:17:31
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, a...
CVE-2026-106033
- EPSS 0.24%
- Veröffentlicht 06.10.2026 18:18:06
- Zuletzt bearbeitet 07.10.2026 12:17:08
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query paramete...
CVE-2026-94416
- EPSS 0.45%
- Veröffentlicht 24.09.2026 12:25:11
- Zuletzt bearbeitet 24.09.2026 16:17:26
An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted t...
CVE-2026-84724
- EPSS 0.29%
- Veröffentlicht 23.09.2026 19:40:42
- Zuletzt bearbeitet 26.09.2026 23:16:38
An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the integer validation defined elsewher...
CVE-2026-84720
- EPSS 0.27%
- Veröffentlicht 23.09.2026 19:40:36
- Zuletzt bearbeitet 24.09.2026 15:17:45
A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats artifacts propagated between workflow nodes, is not wrapped in prevent_search() a...
CVE-2026-84718
- EPSS 0.14%
- Veröffentlicht 23.09.2026 19:40:33
- Zuletzt bearbeitet 24.09.2026 15:17:45
A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts the client-supplied X-Forwarded-For header as the request's client IP without verifying that it originated from ...
CVE-2026-84717
- EPSS 0.34%
- Veröffentlicht 23.09.2026 19:40:32
- Zuletzt bearbeitet 26.09.2026 23:16:37
A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, ca...
CVE-2026-84716
- EPSS 0.18%
- Veröffentlicht 23.09.2026 19:40:28
- Zuletzt bearbeitet 24.09.2026 16:17:12
A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop node's install bundle, the controller signs an X.509 certific...
CVE-2026-84713
- EPSS 0.31%
- Veröffentlicht 23.09.2026 19:40:26
- Zuletzt bearbeitet 25.09.2026 18:17:31
A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in cl...
CVE-2026-84712
- EPSS 0.34%
- Veröffentlicht 23.09.2026 19:40:22
- Zuletzt bearbeitet 24.09.2026 21:00:46
A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonym...