Impact
A flaw in Red Hat Ansible Automation Platform 2 allows a minimally privileged or unauthenticated attacker to read the provisioning-callback secret (host_config_key) from the job template API or activity stream because only the read-level view_jobtemplate permission is sufficient. By combining this leaked secret with an attacker-controlled X-Forwarded-For header, the callback endpoint can be tricked into believing the request originates from any host in the job template’s inventory. The attacker can then trigger the job template against arbitrary managed hosts using the template’s credentials, resulting in privilege escalation and remote code execution on those hosts.
Affected Systems
Red Hat Ansible Automation Platform 2 is affected. The issue applies to Red Hat Automation Platform 2 as distributed by Red Hat, with no specific sub-versions listed beyond the major release 2. Users running this product should verify whether their deployment has provisioning callbacks enabled and whether the host_config_key is exposed in job templates.
Risk and Exploitability
The CVSS base score of 9.9 classifies the vulnerability as critical, and although an EPSS score is not available, the lack of a public KEV listing does not diminish the severity of the impact. An attacker can exploit the flaw remotely, using only a low-privilege account or no authentication, to execute arbitrary commands on any target host where the job template has been configured. Because the vulnerability allows elevation of privileges on remote systems, it represents a high risk to infrastructure and requires urgent mitigation.
OpenCVE Enrichment