Information Disclosure Vulnerability in Ansible Collection by Red Hat
CVE-2026-68562
6.2MEDIUM
What is CVE-2026-68562?
A flaw exists in the Ansible Collection Red Hat Leapp that allows an attacker with privileged write access to the Leapp report on a managed node to manipulate it. When a remediation task is executed by the operator, this compromised report can lead the Ansible controller to access and copy its own local files to the managed node. This issue may result in the disclosure of sensitive information, including private keys and other credentials from the controller.
References
CVSS V3.1
Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.