OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84499

HIGH · CVSS 7.7 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A vulnerability in the Red Hat Ansible Automation Platform's automation-controller allows a user with the JobTemplate Admin role to exploit revalidation of survey questions of type password, revealing stored passwords in plaintext through error messages. This flaw poses a significant risk as it enables unauthorized access to sensitive credentials, potentially compromising workflows and automation processes. Organizations utilizing this platform should prioritize addressing this vulnerability to safeguard their automation environments and protect sensitive information.

CVE
CVE-2026-84499
Severity
HIGH
CVSS
7.7
EPSS
0.38%

Original NVD Description

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and includes its plaintext value in the minimum/maximum length validation error message returned in the HTTP response. A user with the delegated JobTemplate Admin role can tighten the survey length constraint and trigger revalidation of a schedule or node created by another, higher-privileged user, thereby recovering that user's stored password in plaintext.