automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant
Published Sep 23, 2026
5.0
MEDIUMCVSS 3.1
Description
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. A project has a signature validation credential foreign key used to validate signed project content. Unlike the project's SCM credential, the authorization logic does not verify that the requesting user has use permission on the referenced credential, and the API field has no validator or type restriction. An authenticated user holding only the organization project administrator role can therefore bind an arbitrary credential belonging to another organization, by its identifier, when creating or updating a project. The controller discloses that credential's name and type in the project's summary information and, during project synchronization, decrypts the bound credential and uses it in the attacker-controlled project's update, allowing a cross-tenant authorization boundary violation and information disclosure.
Affected products
No data.
No data.
No data.
Red Hat Ansible Automation Platform 2.5 for RHEL 8
automation-controller-0:4.6.33-1.el8ap
Fixed · RHSA-2026:71114
Red Hat Ansible Automation Platform 2.5 for RHEL 9
automation-controller-0:4.6.33-1.el9ap
Fixed · RHSA-2026:71114
Red Hat Ansible Automation Platform 2.6
ansible-automation-platform-26/controller-rhel9:1789673739
Fixed · RHSA-2026:71179
Red Hat Ansible Automation Platform 2.6 for RHEL 9
automation-controller-0:4.7.17-1.el9ap
Fixed · RHSA-2026:71113
Red Hat Ansible Automation Platform 2.7
ansible-automation-platform-27/controller-rhel9:1789580684
Fixed · RHSA-2026:71177
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Ansible Automation Platform 2.5 for RHEL 8 | automation-controller-0:4.6.33-1.el8ap | Fixed | RHSA-2026:71114 |
| Red Hat Ansible Automation Platform 2.5 for RHEL 9 | automation-controller-0:4.6.33-1.el9ap | Fixed | RHSA-2026:71114 |
| Red Hat Ansible Automation Platform 2.6 | ansible-automation-platform-26/controller-rhel9:1789673739 | Fixed | RHSA-2026:71179 |
| Red Hat Ansible Automation Platform 2.6 for RHEL 9 | automation-controller-0:4.7.17-1.el9ap | Fixed | RHSA-2026:71113 |
| Red Hat Ansible Automation Platform 2.7 | ansible-automation-platform-27/controller-rhel9:1789580684 | Fixed | RHSA-2026:71177 |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw affects automation-controller as shipped in Red Hat Ansible Automation Platform. Exploitation requires an authenticated user holding the Organization Project Admin role; the impact is a cross-tenant authorization boundary violation, disclosing another organization's credential metadata and causing server-side use of that credential during project synchronization.
References (4)
- https://access.redhat.com/security/cve/CVE-2026-84643 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2527112 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-84643
- https://www.cve.org/CVERecord?id=CVE-2026-84643
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-84643 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2527112 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-84643 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-84643 |
Change history (0)
No recorded changes yet.