Missing Authentication in Remote-Execution Tasks for Smart Proxy Dynamically Executed by Red Hat
CVE-2026-107151
5.9MEDIUM
What is CVE-2026-107151?
A missing authentication vulnerability has been identified in the smart_proxy_dynflow package, which facilitates remote-execution task updates. This issue allows an attacker who already knows the identifier of a running job to manipulate job output without a required one-time authentication token. When the remote execution mode is set to pull or pull-mqtt, such the attacker could falsely report the job's success or failure, impacting the integrity of job logs and operations.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Arpit Jain (Independent Security Researcher) for reporting this issue.