Sceawere

Vulnerability Detail

CVE-2026-103869UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Pulp-ansible Token Reuse Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
Red Hat
Product
Red Hat Ansible Automation Platform 2
Attack Type
Exposure of Data Element to Wrong Session
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-07T06:16:35.207Z",
  "pubdate": "2026-10-07T06:16:35.207Z",
  "executiveSummary": "This vulnerability in pulp-ansible involves an improper credential management flaw within the bearer-token refresh mechanism for collection remotes.\nThe root cause is the storage of access tokens in a shared, module-level variable, which leads to token leakage across different synchronization tasks executed within the same worker process.\nAn authenticated user with the ability to configure an Ansible remote can exploit this flaw by pointing the remote to a malicious, attacker-controlled server.\nBy triggering a token refresh, the attacker can intercept and capture access tokens intended for different, legitimate remotes.\nThis allows the attacker to impersonate the legitimate remote's identity to the issuing service, potentially leading to unauthorized access or data exposure.\nThe vulnerability does not result in the modification of stored content or service disruption, but it significantly compromises the integrity of the authentication process for collection remotes.\nThe risk is categorized as moderate to high, depending on the scope of the hijacked tokens' permissions within the external services.",
  "technicalDetails": "The vulnerability resides in the implementation of the bearer-token refresh logic for collection remotes within the pulp-ansible component. The application improperly caches sensitive authentication credentials in a module-level variable rather than scoped within the specific instance or execution context of the sync process.\nIn a multi-tenant or shared-worker environment, this stateful caching mechanism causes the access token generated for one synchronization task to persist and be erroneously reused by subsequent tasks assigned to the same worker process.\nThe exploitation flow begins when an attacker, possessing the privileges to configure an Ansible remote, points the remote configuration to an adversary-controlled server. When the Pulp worker initiates a synchronization process for this malicious remote, the token refresh logic is triggered.\nIf the worker process has previously handled authentication for a different, legitimate remote, the shared module-level variable may contain the active bearer token for that legitimate connection. The malicious server, acting as the authentication endpoint, can receive this previously cached token or trick the worker into exposing it during the refresh handshake.\nConsequently, the attacker obtains a valid bearer token intended for a different, potentially more privileged or sensitive remote. Because this token is still valid with the issuing service, the attacker can use the exfiltrated credential to authenticate against that service as if they were the legitimate remote.\nThe vulnerability is fundamentally a consequence of poor state management in the token acquisition workflow, where sensitive identity tokens are leaked due to improper namespace isolation within the Python module. This allows for cross-request credential contamination, as the worker process fails to clear or correctly segregate authentication data between distinct synchronization operations.\nPost-exploitation, the attacker possesses a valid credential that can be used outside of the Pulp environment to interact with any service that trusted the original token. This bypasses the security boundaries intended to isolate remote configurations from one another. While the internal Pulp content remains untampered, the trust relationship between the Pulp worker and external collection servers is effectively subverted, leading to potential unauthorized data exfiltration from those external services."
}
CVE-2026-103869: Pulp-ansible Token Reuse Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere