Access Token Vulnerability in Pulp-Ansible for Remote Collection Synchronization
CVE-2026-103869

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
7 October 2026

What is CVE-2026-103869?

A vulnerability exists in Pulp-Ansible related to the handling of bearer tokens during collection remote syncs. Specifically, an access token, which should be unique for each session, is stored in a module-level variable and reused across multiple token download requests. This flaw permits a user who has successfully synchronized an Ansible remote capable of token refresh to gain access to an access token meant for a different remote server. If this malicious user points their remote to a server they control, they can exploit the token for unauthorized actions at the service that issued it. The integrity of data in Pulp remains intact, as stored content isn't altered and the service continues to operate.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Daoqing Yu for reporting this issue.
.