Insufficient Access Control in Ansible Tower's JobTemplate Functionality
CVE-2026-76648
8.5HIGH
What is CVE-2026-76648?
This vulnerability in Ansible Tower, specifically within the JobTemplate functionality, stems from improper verification of permissions during object creation and copying processes. While the GET requests effectively enforce reading permissions through user role checks, the POST requests lack sufficient validation, exposing a significant risk where users may execute actions without the necessary access rights. This oversight could lead to unauthorized actions against JobTemplates, potentially compromising the integrity and security of sensitive operational data.
References
CVSS V3.1
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Chris Meyers for reporting this issue.