Impact
The flaw allows any authenticated user to query the /api/v2/config/ endpoint and retrieve sensitive license information, such as account numbers, subscription IDs, pool IDs, SKU, support level, and instance counts. This data can be used for social engineering against Red Hat support and to gauge an organization’s estate sizing, and the vulnerability stems from an improper authorization check (CWE‑862).
Affected Systems
Red Hat Ansible Automation Platform 2 (automation controller). Any deployment of the automation controller component that exposes the /api/v2/config/ API is affected. No specific version information is provided in the advisory.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, largely due to confidentiality impact. Exploitation requires only authentication, so the risk is limited by the number of users with legitimate access. EPSS data are unavailable and the issue is not listed in CISA’s KEV catalog, suggesting no public exploitation is currently known. Nonetheless, harvested information could be leveraged by attackers who obtain or guess credentials through social engineering or credential compromise.
OpenCVE Enrichment