Vulnerability in Ansible Automation Platform Affects Bitbucket Data Center Webhooks
CVE-2026-84717
5.3MEDIUM
What is CVE-2026-84717?
A vulnerability exists in the Ansible Automation Platform automation-controller related to the handling of Bitbucket Data Center webhook requests. Specifically, the HMAC signature verification is bypassed for 'diagnostics:ping' events after the target template has been verified. This flaw allows an unauthenticated remote attacker to exploit the response differences—receiving an HTTP 200 for configured Job Template IDs and HTTP 403 for others. By leveraging this behavior, attackers can indirectly enumerate which Job Template and Workflow Job Template IDs have associated Bitbucket DC webhooks, thereby gaining insights into the configuration without requiring the secret 'webhook_key'.