Impact
An unauthorized debug interface inside Red Hat Ansible Automation Platform 2 exposes scheduler‑trigger endpoints that do not require authentication. An unauthenticated remote attacker can repeatedly call these paths, repeatedly acquiring the global scheduler advisory lock. Because the legitimate scheduler also needs the same lock, the attacker effectively starves the scheduler, causing real job runs to be skipped and delaying job dispatch for all tenants. The flaw leads to a denial of service that also consumes controller web‑worker resources, matching CWE‑489.
Affected Systems
The vulnerability resides in the automation‑controller component of Red Hat Ansible Automation Platform 2. The affected build includes the unauthenticated debug views and the debug root view that exposes the available debug endpoints. No specific minor version is listed; any installation of platform 2 requires assessment. The issue is present only in production‑grade builds where the debug setting is not gated on the URLs.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, and the exploit probability is unknown (EPSS not available). The vulnerability is exploitable over the network via HTTP without credentials, with no known mitigating configuration changes. Because it is listed as not in CISA KEV, an active exploitation campaign has not yet been reported, but the effect of lock starvation can severely disrupt service availability. Immediate patching or access restriction is advised.
OpenCVE Enrichment