Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-103869— Pulp-ansible: bearer tokens are reused across remotes in a worker

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

发现 Pulp-Ansible 在处理集远程(collection remotes)的承载令牌(bearer-token)刷新时存在一个缺陷。访问令牌被保存在一个模块级别的变量中,并在该工作进程中重复用于所有令牌下载操作。攻击者若能同步一个使用令牌刷新的 Ansible 远程,并将该远程指向其控制的服务器,即可获得另一个远程所对应的访问令牌,并在签发该令牌的服务端重复使用此令牌。Pulp 中存储的内容不会被更改,服务也不会中断。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1528 · Steal Application Access Token
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-103869

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Pulp-ansible: bearer tokens are reused across remotes in a worker
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对错误会话暴露数据元素
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6

II. Public POCs for CVE-2026-103869

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-103869

请登录查看更多情报信息。

Other References for CVE-2026-103869 (2)

Same Patch Batch · Red Hat · 2026-10-07 · 6 CVEs total

CVE-2026-106471 8.1 HIGH Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter mult
CVE-2026-107121 6.5 MEDIUM Keycloak-services: keycloak-services: smtp starttls plaintext credential and message downg
CVE-2026-103868 6.5 MEDIUM Pulp-container: registry credentials are reused across remotes in a worker
CVE-2026-106061 5.5 MEDIUM Gimp: gimp: heap buffer over-read in x cursor (xmc) thumbnail loader on crafted file
CVE-2026-103870 5.0 MEDIUM Pulp-rpm: distribution tree publish creates directories from .treeinfo ids

IV. Related Vulnerabilities

V. Comments for CVE-2026-103869

No comments yet


Leave a comment