CVE-2026-71461: Generation of Error Message Containing Sensitive Information in Red Hat Red Hat Ansible Automation Platform 2
HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.
AI Analysis
Technical Summary
The vulnerability arises from HostList.list() catching all exceptions and returning the exception message string directly. By using the host_filter parameter, an authenticated user can cause Django FieldError exceptions that reveal the complete Host model relation graph, including internal reverse accessors, or PostgreSQL DataError exceptions that leak raw database error messages. Specifically, using credential__search=x exposes the ORM schema, and name__regex=[bad triggers PostgreSQL error reflections. This results in information disclosure of internal application and database schema details.
Potential Impact
The vulnerability leads to information disclosure of sensitive internal data structures, including the ORM schema and database error messages. This could aid an attacker in understanding the internal workings of the application and database, potentially facilitating further attacks. The CVSS score of 4.3 indicates a medium severity impact with confidentiality loss but no integrity or availability impact.
Mitigation Recommendations
The vendor advisory from Red Hat should be consulted for the official remediation status. No patch or fix information is provided in the input data. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-71461 for current remediation guidance. Until a fix is applied, limit authenticated user access to trusted users and avoid exposing the vulnerable functionality unnecessarily.
CVE-2026-71461: Generation of Error Message Containing Sensitive Information in Red Hat Red Hat Ansible Automation Platform 2
Description
HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.
CVSS v3.1
Score 4.3medium
Affected software
Red Hat
Red Hat Ansible Automation Platform 2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises from HostList.list() catching all exceptions and returning the exception message string directly. By using the host_filter parameter, an authenticated user can cause Django FieldError exceptions that reveal the complete Host model relation graph, including internal reverse accessors, or PostgreSQL DataError exceptions that leak raw database error messages. Specifically, using credential__search=x exposes the ORM schema, and name__regex=[bad triggers PostgreSQL error reflections. This results in information disclosure of internal application and database schema details.
Potential Impact
The vulnerability leads to information disclosure of sensitive internal data structures, including the ORM schema and database error messages. This could aid an attacker in understanding the internal workings of the application and database, potentially facilitating further attacks. The CVSS score of 4.3 indicates a medium severity impact with confidentiality loss but no integrity or availability impact.
Mitigation Recommendations
The vendor advisory from Red Hat should be consulted for the official remediation status. No patch or fix information is provided in the input data. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-71461 for current remediation guidance. Until a fix is applied, limit authenticated user access to trusted users and avoid exposing the vulnerable functionality unnecessarily.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-06T19:31:51.453Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-71461","vendor":"Red Hat"}]
Threat ID: 6ab41efff7a7c541062f1a8c
Added to database: 09/23/2026, 18:48:31 UTC
Last enriched: 09/23/2026, 19:04:32 UTC
Last updated: 09/24/2026, 02:13:18 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.