A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.

Project Subscriptions

Vendors Products
Ansible Automation Platform Subscribe
Satellite Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

History

Wed, 07 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.
Title Pulp-ansible: bearer tokens are reused across remotes in a worker
First Time appeared Redhat
Redhat ansible Automation Platform
Redhat satellite
Weaknesses CWE-488
CPEs cpe:/a:redhat:ansible_automation_platform:2
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat ansible Automation Platform
Redhat satellite
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T07:19:18.804Z

Reserved: 2026-10-01T11:51:10.972Z

Link: CVE-2026-103869

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T06:16:35.207

Modified: 2026-10-07T07:16:57.463

Link: CVE-2026-103869

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses