{"api_version":"1","generated_at":"2026-09-23T21:50:22+00:00","cve":"CVE-2026-84717","urls":{"html":"https://cve.report/CVE-2026-84717","api":"https://cve.report/api/cve/CVE-2026-84717.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-84717","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-84717"},"summary":{"title":"Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates","description":"A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated\nBitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping\nevents after it has already looked up the target template, causing the endpoint to return HTTP\n200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An\nunauthenticated remote attacker can use this response discrepancy as an oracle to enumerate\nwhich Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without\nknowing the secret webhook_key.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-09-23 20:17:18","updated_at":"2026-09-23 20:17:18"},"problem_types":["CWE-204","CWE-204 Observable Response Discrepancy"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"5.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527210","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2527210","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-84717","name":"https://access.redhat.com/security/cve/CVE-2026-84717","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-84717","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84717","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]},{"source":"CNA","vendor":"Red Hat","product":"Red Hat Ansible Automation Platform 2","version":"","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-02T01:13:15.073Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-09-23T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-26/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"ansible-automation-platform-27/controller-rhel9","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:ansible_automation_platform:2"],"defaultStatus":"affected","packageName":"automation-controller","product":"Red Hat Ansible Automation Platform 2","vendor":"Red Hat"}],"datePublic":"2026-09-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated\nBitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping\nevents after it has already looked up the target template, causing the endpoint to return HTTP\n200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An\nunauthenticated remote attacker can use this response discrepancy as an oracle to enumerate\nwhich Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without\nknowing the secret webhook_key."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Moderate"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-204","description":"Observable Response Discrepancy","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-23T19:40:32.246Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-84717"},{"name":"RHBZ#2527210","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527210"}],"timeline":[{"lang":"en","time":"2026-09-02T01:13:15.073Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-09-23T00:00:00.000Z","value":"Made public."}],"title":"Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-204: Observable Response Discrepancy"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-84717","datePublished":"2026-09-23T19:40:32.246Z","dateReserved":"2026-09-02T01:11:22.759Z","dateUpdated":"2026-09-23T19:40:32.246Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-23 20:17:18","lastModifiedDate":"2026-09-23 20:17:18","problem_types":["CWE-204","CWE-204 Observable Response Discrepancy"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"84717","Ordinal":"1","Title":"Automation-controller: automation-controller: unauthenticated 20","CVE":"CVE-2026-84717","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"84717","Ordinal":"1","NoteData":"A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated\nBitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping\nevents after it has already looked up the target template, causing the endpoint to return HTTP\n200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An\nunauthenticated remote attacker can use this response discrepancy as an oracle to enumerate\nwhich Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without\nknowing the secret webhook_key.","Type":"Description","Title":"Automation-controller: automation-controller: unauthenticated 20"}]}}}