A flaw was found in Red Hat Ansible Automation Platform's automation-controller.
When creating or editing an execution environment, the controller does not verify
that the requesting user has use permission on the container registry credential
referenced by the execution environment; it validates only the organization and
the credential kind. An authenticated user who is an execution-environment admin
of one organization can associate a container registry credential belonging to a
different organization -- one they cannot otherwise read, list, or use -- to an
execution environment they control. When a job runs with that execution
environment, the controller decrypts the foreign credential's registry password
and supplies it to the container runtime, disclosing another organization's
registry credentials across the tenant boundary.
When creating or editing an execution environment, the controller does not verify
that the requesting user has use permission on the container registry credential
referenced by the execution environment; it validates only the organization and
the credential kind. An authenticated user who is an execution-environment admin
of one organization can associate a container registry credential belonging to a
different organization -- one they cannot otherwise read, list, or use -- to an
execution environment they control. When a job runs with that execution
environment, the controller decrypts the foreign credential's registry password
and supplies it to the container runtime, disclosing another organization's
registry credentials across the tenant boundary.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Red Hat Ansible Automation Platform's automation-controller. When creating or editing an execution environment, the controller does not verify that the requesting user has use permission on the container registry credential referenced by the execution environment; it validates only the organization and the credential kind. An authenticated user who is an execution-environment admin of one organization can associate a container registry credential belonging to a different organization -- one they cannot otherwise read, list, or use -- to an execution environment they control. When a job runs with that execution environment, the controller decrypts the foreign credential's registry password and supplies it to the container runtime, disclosing another organization's registry credentials across the tenant boundary. | |
| Title | automation-controller: automation-controller-container: automation-controller: execution environment credential foreign key is not use-permission checked, allowing an organization execution-environment admin to bind and disclose another organization's container registry credential (cross-tenant credential disclosure) | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.6::el9 | |
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Projects
Sign in to view the affected projects.
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses