CVE-2026-103869

MEDIUM CVSS 3.1: 6.5 EPSS 0.23%
Updated Oct 07, 2026
Ansible
Parameter Value
CVSS 6.5 (MEDIUM)
Type CWE-488
Vendor Ansible
Public PoC No

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it.

Content stored in Pulp is not changed, and the service is not stopped.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat satellite 6 red hat:red hat ansible automation platform 2