Access Token Vulnerability in Pulp-Ansible for Remote Collection Synchronization
CVE-2026-103869
What is CVE-2026-103869?
A vulnerability exists in Pulp-Ansible related to the handling of bearer tokens during collection remote syncs. Specifically, an access token, which should be unique for each session, is stored in a module-level variable and reused across multiple token download requests. This flaw permits a user who has successfully synchronized an Ansible remote capable of token refresh to gain access to an access token meant for a different remote server. If this malicious user points their remote to a server they control, they can exploit the token for unauthorized actions at the service that issued it. The integrity of data in Pulp remains intact, as stored content isn't altered and the service continues to operate.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved