GPU VulnDB

Database/Control plane, storage & DevOps

Ansible automation-controller: Bitbucket DC webhook ping skips HMAC check, enumerating webhook-enabled templates

CVSS 5.3CVE-2026-84717Control plane, storage & DevOpscurated

Impact

The unauthenticated Bitbucket Data Center webhook receiver looks up the target template before deciding to skip HMAC signature verification for diagnostics:ping events, so it answers HTTP 200 for templates that have a Bitbucket DC webhook configured and HTTP 403 for everything else. That difference is an oracle: an unauthenticated caller can walk Job Template and Workflow Job Template IDs and learn which ones are webhook-triggered, without knowing webhook_key. It leaks nothing but structure, yet it tells an attacker exactly which automation entry points are worth attacking next on a controller that drives fleet configuration. Confidentiality impact is low and there is no integrity or availability effect.

Who can reach it

Anyone who can reach the automation-controller webhook endpoint over the network, with no credentials and no webhook secret. Exposure depends on whether the controller's webhook path is reachable beyond your Bitbucket instance.

What to do

Apply the automation-controller errata (RHSA-2026:71113, 71114, 71177, 71179) for your AAP channel and restart the controller services; no node drain. Where patching must wait, restrict the webhook endpoint at the ingress to your Bitbucket Data Center source addresses.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.