Vulnerability in Ansible Automation Platform Affects Bitbucket Data Center Webhooks
CVE-2026-84717

5.3MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 September 2026

What is CVE-2026-84717?

A vulnerability exists in the Ansible Automation Platform automation-controller related to the handling of Bitbucket Data Center webhook requests. Specifically, the HMAC signature verification is bypassed for 'diagnostics:ping' events after the target template has been verified. This flaw allows an unauthenticated remote attacker to exploit the response differences—receiving an HTTP 200 for configured Job Template IDs and HTTP 403 for others. By leveraging this behavior, attackers can indirectly enumerate which Job Template and Workflow Job Template IDs have associated Bitbucket DC webhooks, thereby gaining insights into the configuration without requiring the secret 'webhook_key'.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.