{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-103869", "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "state": "PUBLISHED", "assignerShortName": "redhat", "dateReserved": "2026-10-01T11:51:10.972Z", "datePublished": "2026-10-07T05:46:15.585Z", "dateUpdated": "2026-10-07T18:35:24.169Z" }, "containers": { "cna": { "title": "Pulp-ansible: bearer tokens are reused across remotes in a worker", "metrics": [ { "other": { "content": { "value": "Moderate", "namespace": "https://access.redhat.com/security/updates/classification/" }, "type": "Red Hat severity rating" } }, { "cvssV3_1": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 6.5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N", "version": "3.1" }, "format": "CVSS" } ], "descriptions": [ { "lang": "en", "value": "A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped." } ], "affected": [ { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "ansible-automation-platform-24/hub-rhel8", "defaultStatus": "unaffected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "ansible-automation-platform-25/hub-rhel8", "defaultStatus": "unaffected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "ansible-automation-platform-26/hub-rhel9", "defaultStatus": "affected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "ansible-automation-platform-27/hub-rhel9", "defaultStatus": "affected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "python3.11-pulp-ansible", "defaultStatus": "unaffected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "python3.12-pulp-ansible", "defaultStatus": "affected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "python3x-pulp-ansible", "defaultStatus": "unaffected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Ansible Automation Platform 2", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "python-pulp-ansible", "defaultStatus": "unaffected", "cpes": [ "cpe:/a:redhat:ansible_automation_platform:2" ] }, { "vendor": "Red Hat", "product": "Red Hat Satellite 6", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "python3.12-pulp-ansible", "defaultStatus": "affected", "cpes": [ "cpe:/a:redhat:satellite:6" ] }, { "vendor": "Red Hat", "product": "Red Hat Satellite 6", "collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "packageName": "python-pulp-ansible", "defaultStatus": "affected", "cpes": [ "cpe:/a:redhat:satellite:6" ] } ], "references": [ { "url": "https://access.redhat.com/security/cve/CVE-2026-103869", "tags": [ "vdb-entry", "x_refsource_REDHAT" ] }, { "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2544603", "name": "RHBZ#2544603", "tags": [ "issue-tracking", "x_refsource_REDHAT" ] } ], "datePublic": "2026-10-07T05:34:40.082Z", "problemTypes": [ { "descriptions": [ { "cweId": "CWE-488", "description": "Exposure of Data Element to Wrong Session", "lang": "en", "type": "CWE" } ] } ], "x_redhatCweChain": "CWE-488: Exposure of Data Element to Wrong Session", "workarounds": [ { "lang": "en", "value": "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available." } ], "timeline": [ { "lang": "en", "time": "2026-10-01T11:46:24.602Z", "value": "Reported to Red Hat." }, { "lang": "en", "time": "2026-10-07T05:34:40.082Z", "value": "Made public." } ], "credits": [ { "lang": "en", "value": "Red Hat would like to thank gwolfs (Independent Security Researcher) for reporting this issue." } ], "providerMetadata": { "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749", "shortName": "redhat", "dateUpdated": "2026-10-07T17:36:00.854Z" }, "x_generator": { "engine": "cvelib 1.8.0" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T18:35:07.877185Z", "id": "CVE-2026-103869", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T18:35:24.169Z" } } ] } }