Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped. | |
| Title | Pulp-ansible: bearer tokens are reused across remotes in a worker | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat satellite |
|
| Weaknesses | CWE-488 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T07:19:18.804Z
Reserved: 2026-10-01T11:51:10.972Z
Link: CVE-2026-103869
No data.
Status : Received
Published: 2026-10-07T06:16:35.207
Modified: 2026-10-07T07:16:57.463
Link: CVE-2026-103869
No data.
OpenCVE Enrichment
No data.
-
CWE-488
Exposure of Data Element to Wrong Session