Evidence used
- No CISA KEV confirmation is currently recorded.
BlackTreeCVE IntelligenceRed Hat Product Security · automation-controller.src as a component of Red Hat Ansible Automation Platform 2
Red Hat Product Security reports a high vendor CVSS assessment and supplies remediation evidence. Validate product applicability and exposure while canonical CVE data is pending.
Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.
The vendor explicitly identifies these products as affected by this CVE.
Red Hat Product Security reports a high vendor CVSS assessment and supplies remediation evidence. Validate product applicability and exposure while canonical CVE data is pending.
Patch availableautomation-controller: InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle
automation-controller: InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
automation-controller: InventorySource.source_vars lacks prevent_search, enabling zero-privilege cross-tenant extraction of inline inventory-plugin credentials via the credential_types FieldLookupBackend count-oracle
The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
An attacker operating through a network path may attempt exploitation with low privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-204: Observable Response Discrepancy. The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:NCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Linked articles are downloaded and versioned as source evidence. A CVE mention or approved update relationship does not, by itself, verify a fix for every product branch.
Published 23 Sept 2026 · Last source change 24 Sept 2026, 05:58 UTC · CWE-204 · Observable Response Discrepancy
Missing structured fields: official CVE record, canonical affected-version range. Missing data is not evidence of low risk; review the primary advisory.