๐Ÿ” CVE Alert

CVE-2026-84717

MEDIUM 5.3

Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.

CWE CWE-204
Vendor red hat
Product red hat ansible automation platform 2.6 for rhel 9
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat ansible automation platform 2.6 for rhel 9

Be the first to know when new medium vulnerabilities affecting red hat red hat ansible automation platform 2.6 for rhel 9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Red Hat / Red Hat Ansible Automation Platform 2.6 for RHEL 9
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected
Red Hat / Red Hat Ansible Automation Platform 2
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:71113 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-84717 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2527210