CVE-2026-103869 PUBLISHED

Pulp-ansible: bearer tokens are reused across remotes in a worker

Assigner: redhat
Reserved: 01.10.2026 Published: 07.10.2026 Updated: 07.10.2026

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: unaffected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: unaffected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: affected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: affected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: unaffected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: affected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: unaffected
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2
Versions Default: unaffected
Vendor Red Hat
Product Red Hat Satellite 6
Versions Default: affected
Vendor Red Hat
Product Red Hat Satellite 6
Versions Default: affected

Workarounds

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Credits

  • Red Hat would like to thank Daoqing Yu for reporting this issue.

References

Problem Types

  • Exposure of Data Element to Wrong Session CWE