GPU VulnDB

Database/Control plane, storage & DevOps

Ansible automation-controller: survey length-validation error leaks a stored password in plaintext

CVSS 7.7CVE-2026-84499Control plane, storage & DevOpscurated

Impact

Survey answers of type password are stored encrypted and shown only as a placeholder, but when a schedule or workflow job template node is revalidated against a tightened survey spec, automation-controller decrypts the stored value and includes it verbatim in the min/max-length validation error returned in the HTTP response. A user holding only the delegated JobTemplate Admin role can tighten the length constraint and force revalidation of a schedule created by a more privileged user, reading back that user's secret. In a datacenter that drives fleet provisioning, BMC and firmware workflows through AAP, those survey passwords are commonly BMC, switch, registry or cloud credentials - so this is a privilege-escalation path from template admin to whatever the fleet automation can reach. Confidentiality only; nothing is modified.

Who can reach it

Authenticated over the network to the automation-controller API or UI, holding the delegated JobTemplate Admin role on a template whose survey another user answered. No host access needed.

What to do

Apply the Red Hat errata for your AAP stream (RHSA-2026:71113/71114 for 2.5 on RHEL 8/9, RHSA-2026:71177/71179) and restart the automation-controller services - a control-plane service restart, no node reboot. Treat any password-type survey answer that a JobTemplate Admin could have reached as exposed and rotate it; review who holds that delegated role in the meantime.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.