CVE-2026-84499 Overview
CVE-2026-84499 is an information disclosure flaw in Red Hat Ansible Automation Platform's automation-controller. Survey questions of type password are stored encrypted and are meant to be write-only, appearing only as a placeholder when read back. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller decrypts the stored password and embeds its plaintext value in the length validation error message returned in the HTTP response. This weakness is classified as Information Exposure Through an Error Message [CWE-209].
Critical Impact
A user holding the delegated JobTemplate Admin role can tighten a survey length constraint, trigger revalidation, and recover plaintext passwords stored by higher-privileged users.
Affected Products
- Red Hat Ansible Automation Platform (automation-controller component)
- Fixed packages listed in Red Hat Security Advisories RHSA-2026:71113 and RHSA-2026:71114
- Fixed packages listed in Red Hat Security Advisories RHSA-2026:71177 and RHSA-2026:71179
Discovery Timeline
- 2026-09-23 - CVE-2026-84499 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-84499
Vulnerability Analysis
Ansible Automation Platform surveys collect runtime input for job templates. Fields declared as type password are encrypted at rest and returned as placeholder strings on read operations, preserving confidentiality of secrets like API tokens, service account credentials, and privileged passwords.
When an administrator modifies an existing survey to tighten minimum or maximum length constraints, the controller must revalidate previously-created schedules and workflow job template nodes against the new specification. During this revalidation, the controller decrypts the stored password to measure its length. If the length falls outside the new bounds, the controller constructs a validation error and includes the decrypted value directly in the HTTP response body.
The attack becomes cross-privilege because the JobTemplate Admin role is delegable. A lower-privileged admin can modify surveys attached to schedules or nodes originally configured by higher-privileged operators, causing the controller to leak those users' secrets.
Root Cause
The root cause is verbose error handling that includes sensitive input values in validation messages. The survey subsystem trusts that password fields will never be reflected back to clients, but the length-validation code path bypasses that contract by decrypting the ciphertext for measurement and then serializing the plaintext into the error response.
Attack Vector
Exploitation requires network access to the automation-controller API and authenticated access with the JobTemplate Admin role on the target job template. The attacker edits the survey specification to set a min or max length that the stored password cannot satisfy. The attacker then triggers revalidation of an existing schedule or workflow node created by a higher-privileged user. The controller responds with an HTTP 400 validation error whose body contains the plaintext password. No user interaction from the victim is required, and the attack succeeds even though the attacker never had permission to read the secret directly.
Refer to the Red Hat CVE detail page and Red Hat Bugzilla #2527090 for vendor technical analysis.
Detection Methods for CVE-2026-84499
Indicators of Compromise
- HTTP 400 responses from automation-controller survey or schedule endpoints containing unexpectedly long strings in min_length/max_length validation error fields.
- Audit log entries showing survey specification edits followed immediately by schedule or workflow node revalidation requests by the same user.
- Repeated PATCH or PUT operations against /api/v2/job_templates/*/survey_spec/ from accounts holding only JobTemplate Admin privileges.
Detection Strategies
- Alert on any survey survey_spec modification that reduces max or increases min length constraints on password-type questions.
- Correlate survey edits with subsequent 4xx responses from /api/v2/schedules/ and workflow node validation endpoints performed by the same principal within a short window.
- Review automation-controller application logs for validation error messages associated with password-type survey fields.
Monitoring Recommendations
- Forward automation-controller API access logs and audit logs to a centralized analytics platform for query and retention.
- Baseline expected survey editing behavior per role and flag deviations, particularly changes performed by delegated admins on templates owned by higher-privileged users.
- Monitor role assignments for the JobTemplate Admin role and review any new grants against change management records.
How to Mitigate CVE-2026-84499
Immediate Actions Required
- Apply the fixed automation-controller packages from the applicable Red Hat Security Advisory (RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71177, or RHSA-2026:71179) matching your product channel.
- Rotate any passwords, tokens, or secrets previously stored in password-type survey fields on affected controllers.
- Audit JobTemplate Admin role assignments and revoke delegations that are not operationally required.
Patch Information
Red Hat has published fixed packages through four errata: RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71177, and RHSA-2026:71179. Consult the Red Hat CVE page to identify the correct erratum for your subscription channel.
Workarounds
- Until patching is complete, restrict the JobTemplate Admin role to trusted operators only and remove delegations to lower-tier administrators.
- Avoid tightening length constraints on existing surveys that contain password-type questions; recreate the survey and re-enter secrets instead.
- Review existing schedules and workflow job template nodes for stored secrets, and consider rotating credentials sourced from surveys to Ansible Automation Platform credential objects, which are governed by RBAC independently of survey editing.
# Example: apply the vendor fix using the standard package manager
sudo dnf update automation-controller
sudo systemctl restart automation-controller
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
