Impact
A flaw in Red Hat Ansible Automation Platform’s automation‑controller allows a project administrator to bind a signature‑validation credential that belongs to a different organization without verifying the administrator’s use privileges on that credential. When the project is created or updated the controller reveals the bound credential’s name and type in a project summary and later decrypts and uses the credential during project synchronization. This leads to an authorization boundary violation that exposes information about another tenant’s credentials.
Affected Systems
The vulnerability affects the automation‑controller component of Red Hat Ansible Automation Platform 2.6 running on Enterprise Linux 9. Any installation that exposes the project configuration API to an authenticated project administrator is impacted, regardless of the tenant the credential actually belongs to.
Risk and Exploitability
The CVSS score of 5.0 denotes a moderate severity, and the failure to list the vulnerability in CISA’s KEV catalog and the absence of an EPSS score suggest limited current exploitation activity. However, the bug is exploitable via the documented API by any user with project‑administrator rights, allowing cross‑tenant credential discovery and usage. The attack requires authentication but does not need elevated system privileges, making it a realistic threat for internal actors with permission to manage projects.
OpenCVE Enrichment