OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-76648

HIGH · CVSS 8.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects the POST method in the JobTemplate API of the affected products, which lacks proper object-level role-based access control (RBAC) checks, allowing unauthorized users to potentially copy sensitive JobTemplate configurations. This oversight could lead to unauthorized access to critical resources, as the system only verifies if the user can add or copy related objects without confirming read permissions on the source JobTemplate. Organizations using this API should prioritize remediation to prevent potential data exposure and ensure compliance with access control policies.

CVE
CVE-2026-76648
Severity
HIGH
CVSS
8.5
EPSS
0.24%

Original NVD Description

CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines 1001–1010) does not. POST only checks: can_access(model, 'add', create_kwargs_check) can_access(model, 'copy_related', obj) For JobTemplate, can_add (awx/awx/main/access.py:1465–1520) gates on inventory.use_role + project.use_role + execution_environment.read_role — resource-level roles that do not imply read on the source JT — and can_copy_related (1522–1534) checks only credentials.use_role. None of these imply the caller can read the source JT.