A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. A project has a signature validation credential foreign key used to
validate signed project content. Unlike the project's SCM credential, the
authorization logic does not verify that the requesting user has use permission
on the referenced credential, and the API field has no validator or type
restriction. An authenticated user holding only the organization project
administrator role can therefore bind an arbitrary credential belonging to
another organization, by its identifier, when creating or updating a project.
The controller discloses that credential's name and type in the project's
summary information and, during project synchronization, decrypts the bound
credential and uses it in the attacker-controlled project's update, allowing a
cross-tenant authorization boundary violation and information disclosure.
controller. A project has a signature validation credential foreign key used to
validate signed project content. Unlike the project's SCM credential, the
authorization logic does not verify that the requesting user has use permission
on the referenced credential, and the API field has no validator or type
restriction. An authenticated user holding only the organization project
administrator role can therefore bind an arbitrary credential belonging to
another organization, by its identifier, when creating or updating a project.
The controller discloses that credential's name and type in the project's
summary information and, during project synchronization, decrypts the bound
credential and uses it in the attacker-controlled project's update, allowing a
cross-tenant authorization boundary violation and information disclosure.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. A project has a signature validation credential foreign key used to validate signed project content. Unlike the project's SCM credential, the authorization logic does not verify that the requesting user has use permission on the referenced credential, and the API field has no validator or type restriction. An authenticated user holding only the organization project administrator role can therefore bind an arbitrary credential belonging to another organization, by its identifier, when creating or updating a project. The controller discloses that credential's name and type in the project's summary information and, during project synchronization, decrypts the bound credential and uses it in the attacker-controlled project's update, allowing a cross-tenant authorization boundary violation and information disclosure. | |
| Title | automation-controller: automation-controller-container: automation-controller: missing use_role authorization on the project signature validation credential foreign key allows a project administrator to bind and use another organization's credential cross-tenant | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.6::el9 | |
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-09-24T01:30:12Z
Weaknesses