subsystem. Although NotificationTemplate.notification_
configuration is protected from API filtering, its recipient
value is copied in clear text into the unprotected
Notification.recipients field on every send. Because the
credential-types endpoint is listable by any authenticated
user and the API filter backend traverses object relations
without per-hop authorization, a user with no privileges can
use a relational filter as a boolean count-oracle to recover,
character by character and across organizations, the secret
recipient values of other tenants' notifications — including
PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook
bearer-token URLs. This flaw affects confidentiality.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is protected from API filtering, its recipient value is copied in clear text into the unprotected Notification.recipients field on every send. Because the credential-types endpoint is listable by any authenticated user and the API filter backend traverses object relations without per-hop authorization, a user with no privileges can use a relational filter as a boolean count-oracle to recover, character by character and across organizations, the secret recipient values of other tenants' notifications — including PagerDuty service keys and Slack/Mattermost/RocketChat/Webhook bearer-token URLs. This flaw affects confidentiality. | |
| Title | Automation-controller: automation-controller: notification.recipients/subject/error lack prevent_search, allowing zero-privilege cross-tenant recovery of notification recipient secrets via filter oracle | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 | |
| Vendors & Products |
Redhat
Redhat ansible Automation Platform |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-23T19:40:26.061Z
Reserved: 2026-09-02T00:50:40.363Z
Link: CVE-2026-84713
No data.
Status : Received
Published: 2026-09-23T20:17:17.950
Modified: 2026-09-23T20:17:17.950
Link: CVE-2026-84713
No data.
OpenCVE Enrichment
Updated: 2026-09-23T20:30:09Z
-
CWE-639
Authorization Bypass Through User-Controlled Key