Description
A flaw was found in Red Hat Ansible Automation Platform's automation-
controller. When attaching a source inventory to a constructed inventory through
the input_inventories relationship endpoint, the controller verifies only that
the requesting user can read the source inventory, rather than that they hold use
permission on it, unlike instance group attachment on the same access class. An
authenticated user who can administer a constructed inventory and has read-only
visibility of an inventory in another organization -- for example an
organization or system auditor -- can attach that foreign inventory as an input.
On synchronization the controller clones every host and host variable, including
secrets, into the attacker's inventory, and because the attacker administers the
constructed inventory they can run ad hoc commands against the cloned hosts,
resulting in cross-tenant disclosure of inventory data and secrets and code
execution against another tenant's managed hosts.
controller. When attaching a source inventory to a constructed inventory through
the input_inventories relationship endpoint, the controller verifies only that
the requesting user can read the source inventory, rather than that they hold use
permission on it, unlike instance group attachment on the same access class. An
authenticated user who can administer a constructed inventory and has read-only
visibility of an inventory in another organization -- for example an
organization or system auditor -- can attach that foreign inventory as an input.
On synchronization the controller clones every host and host variable, including
secrets, into the attacker's inventory, and because the attacker administers the
constructed inventory they can run ad hoc commands against the cloned hosts,
resulting in cross-tenant disclosure of inventory data and secrets and code
execution against another tenant's managed hosts.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 24 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. When attaching a source inventory to a constructed inventory through the input_inventories relationship endpoint, the controller verifies only that the requesting user can read the source inventory, rather than that they hold use permission on it, unlike instance group attachment on the same access class. An authenticated user who can administer a constructed inventory and has read-only visibility of an inventory in another organization -- for example an organization or system auditor -- can attach that foreign inventory as an input. On synchronization the controller clones every host and host variable, including secrets, into the attacker's inventory, and because the attacker administers the constructed inventory they can run ad hoc commands against the cloned hosts, resulting in cross-tenant disclosure of inventory data and secrets and code execution against another tenant's managed hosts. | |
| Title | automation-controller: automation-controller-container: automation-controller: constructed inventory input inventory attachment checks only read permission on the source inventory, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2.4::el8 cpe:/a:redhat:ansible_automation_platform:2.4::el9 cpe:/a:redhat:ansible_automation_platform:2.6::el9 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses