Evidence used
- No CISA KEV confirmation is currently recorded.
BlackTreeCVE IntelligenceRed Hat Product Security · automation-controller-venv-tower-0:4.6.33-1.el8ap.aarch64 as a component of Red Hat Ansible Automation Platform 2.5 for RHEL 8
Red Hat Product Security has published authoritative product evidence for this CVE. Validate applicability and follow the linked vendor advisory while canonical CVE data is pending.
Structured product status and remediation from the issuing vendor. Product-state explanations are always visible; large lists can be searched or downloaded.
The vendor explicitly identifies these products or versions as containing the fix.
Red Hat Product Security has published authoritative product evidence for this CVE. Validate applicability and follow the linked vendor advisory while canonical CVE data is pending.
Patch availableA flaw was found in Red Hat Ansible Automation Platform's automation-controller. When creating or editing an execution environment, the controller does not verify that the requesting user has use permission on the container registry credential referenced by the execution environment; it validates only the organization and the credential kind. An authenticated user who is an execution-environment admin of one organization can associate a container registry credential belonging to a different organization -- one they cannot otherwise read, list, or use -- to an execution environment they control. When a job runs with that execution environment, the controller decrypts the foreign credential's registry password and supplies it to the container runtime, disclosing another organization's registry credentials across the tenant boundary.
A flaw was found in Red Hat Ansible Automation Platform's automation-controller. When creating or editing an execution environment, the controller does not verify that the requesting user has use permission on the container registry credential referenced by the execution environment; it validates only the organization and the credential kind. An authenticated user who is an execution-environment admin of one organization can associate a container registry credential belonging to a different organization -- one they cannot otherwise read, list, or use -- to an execution environment they control. When a job runs with that execution environment, the controller decrypts the foreign credential's registry password and supplies it to the container runtime, disclosing another organization's registry credentials across the tenant boundary.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
An attacker operating through a network path may attempt exploitation with elevated privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
A flaw was found in Red Hat Ansible Automation Platform's automation-controller. When creating or editing an execution environment, the controller does not verify that the requesting user has use permission on the container registry credential referenced by the execution environment; it validates only the organization and the credential kind. An authenticated user who is an execution-environment admin of one organization can associate a container registry credential belonging to a different organization -- one they cannot otherwise read, list, or use -- to an execution environment they control. When a job runs with that execution environment, the controller decrypts the foreign credential's registry password and supplies it to the container runtime, disclosing another organization's registry credentials across the tenant boundary.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
An attacker operating through a network path may attempt exploitation with elevated privileges. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.
CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.
No CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.
No exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.
CWE-639: Authorization Bypass Through User-Controlled Key. The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:NCommon Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.
Operational remediation based on structured source evidence.
Linked articles are downloaded and versioned as source evidence. A CVE mention or approved update relationship does not, by itself, verify a fix for every product branch.
Published 23 Sept 2026 · Last source change 24 Sept 2026, 06:09 UTC · CWE-639 · Authorization Bypass Through User-Controlled Key
Missing structured fields: official CVE record, canonical affected-version range. Missing data is not evidence of low risk; review the primary advisory.