CVE-2026-71461: Red Hat Ansible Automation Platform 2

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError (leaking complete Host model relation graph including internal reverse accessors) or PostgreSQL DataError (leaking raw database error strings). Two primitives: credential__search=x dumps ORM schema, name__regex=[bad reflects PostgreSQL errors.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Ansible Automation Platform 2.7: before 1789580684 (fixed in 1789580684)

Published 2026-09-23. Last modified 2026-09-26.