A flaw was found in the Ansible Automation Platform automation-controller. (CVE-2026-84717)
A vulnerability in the Ansible Automation Platform automation-controller allows an unauthenticated remote attacker to enumerate Job Template and Workflow Job Template IDs that have Bitbucket Data Center webhooks configured. This occurs because the webhook receiver skips HMAC signature verification for diagnostics:ping events after template lookup, causing different HTTP responses that can be used as an oracle. The issue does not allow direct code execution or data modification but leaks configuration information.
AI Analysis
Technical Summary
CVE-2026-84717 is a vulnerability in the Ansible Automation Platform automation-controller where the unauthenticated Bitbucket Data Center webhook receiver bypasses HMAC signature verification for diagnostics:ping events after looking up the target template. This causes the endpoint to return HTTP 200 for templates with Bitbucket DC webhooks configured and HTTP 403 otherwise. An unauthenticated attacker can exploit this response difference to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured without knowing the secret webhook_key. This information disclosure flaw is rated medium severity with a CVSS score of 5.3.
Potential Impact
An unauthenticated remote attacker can enumerate the presence of Bitbucket Data Center webhooks on job templates by observing HTTP response codes. This leaks configuration information but does not directly allow unauthorized code execution, data modification, or denial of service.
Mitigation Recommendations
A security update is available from Red Hat for Ansible Automation Platform 2.6 that addresses this vulnerability. Users should apply the official patch as per Red Hat Advisory RHSA-2026:71113. No additional mitigation steps are indicated by the vendor advisory.
A flaw was found in the Ansible Automation Platform automation-controller. (CVE-2026-84717)
Description
A vulnerability in the Ansible Automation Platform automation-controller allows an unauthenticated remote attacker to enumerate Job Template and Workflow Job Template IDs that have Bitbucket Data Center webhooks configured. This occurs because the webhook receiver skips HMAC signature verification for diagnostics:ping events after template lookup, causing different HTTP responses that can be used as an oracle. The issue does not allow direct code execution or data modification but leaks configuration information.
CVSS v3.1
Score 5.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-84717 is a vulnerability in the Ansible Automation Platform automation-controller where the unauthenticated Bitbucket Data Center webhook receiver bypasses HMAC signature verification for diagnostics:ping events after looking up the target template. This causes the endpoint to return HTTP 200 for templates with Bitbucket DC webhooks configured and HTTP 403 otherwise. An unauthenticated attacker can exploit this response difference to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured without knowing the secret webhook_key. This information disclosure flaw is rated medium severity with a CVSS score of 5.3.
Potential Impact
An unauthenticated remote attacker can enumerate the presence of Bitbucket Data Center webhooks on job templates by observing HTTP response codes. This leaks configuration information but does not directly allow unauthorized code execution, data modification, or denial of service.
Mitigation Recommendations
A security update is available from Red Hat for Ansible Automation Platform 2.6 that addresses this vulnerability. Users should apply the official patch as per Red Hat Advisory RHSA-2026:71113. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-2r6r-cm6p-cm76
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-84717"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6ab4be23f7a7c54106eee980
Added to database: 09/24/2026, 06:07:31 UTC
Last enriched: 09/24/2026, 06:20:02 UTC
Last updated: 09/24/2026, 22:47:33 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.