CVE-2026-84717
Last modified
CVE-2026-84717 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 8 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-84717?
How severe is CVE-2026-84717?
How do I fix CVE-2026-84717?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-84706A flaw was found in Ansible Automation Platform's automation…7.6
- CVE-2026-84712A flaw was found in the automation-controller API. The …5.3
- CVE-2026-84713A flaw was found in the automation-controller notification …6.5
- CVE-2026-84714A flaw was found in the automation-controller input-validati…7.1
- CVE-2026-84715FeatherPanel versions before 1.3.7.10 fail to validate permi…8.8
- CVE-2026-84716A flaw was found in the automation-controller instance …6.6
- CVE-2026-84718A flaw was found in the Ansible Automation Platform automati…4.3
- CVE-2026-84719A flaw was found in the Ansible Automation Platform automati…9.9
- CVE-2026-8472GitLab has remediated an issue in GitLab EE affecting all ve…4.3
- CVE-2026-84720A flaw was found in the Ansible Automation Platform automati…6.5
- CVE-2026-84721A server-side request forgery flaw was found in the Ansible …6.4
- CVE-2026-84724An argument-injection flaw was found in the Ansible Automati…6.6
Are you affected by CVE-2026-84717?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
