{"id":"CVE-2026-84499","title":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller","summary":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Survey questions of type password are write-only and stored\nencrypted, displayed only as a placeholder on read. When a schedule or\nworkflow job template no…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-209"],"vendor":"Red Hat","product":"automation-controller","affected":["automation-controller (all versions)","ansible-automation-platform-26/controller-rhel9 (all versions)","ansible-automation-platform-27/controller-rhel9 (all versions)"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T23:18:47.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-84499","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-84499","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527090","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-23T19:31:04.470Z","slug":"CVE-2026-84499","body":"## Overview\n\nA flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Survey questions of type password are write-only and stored\nencrypted, displayed only as a placeholder on read. When a schedule or\nworkflow job template node is revalidated against a tightened survey\nspecification, the controller decrypts the stored password and includes its\nplaintext value in the minimum/maximum length validation error message\nreturned in the HTTP response. A user with the delegated JobTemplate Admin\nrole can tighten the survey length constraint and trigger revalidation of a\nschedule or node created by another, higher-privileged user, thereby\nrecovering that user's stored password in plaintext.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}