Database Exposure in Ansible Automation Platform by Red Hat
CVE-2026-84720
6.5MEDIUM
What is CVE-2026-84720?
A flaw exists in Red Hat's Ansible Automation Platform wherein the WorkflowJobNode.ancestor_artifacts database column allows arbitrary field lookups via the REST filter backend. This vulnerability permits users with mere read access or any authenticated users through a regex lookup to potentially retrieve sensitive data that was meant to be protected. Specifically, secrets marked with no_log may be exposed, threatening the confidentiality of playbook authors' sensitive information across organizational boundaries.