CVE-2026-103869: Red Hat Ansible Automation Platform 2
Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.
Affected products
Published 2026-10-07. Last modified 2026-10-07.