CVE-2026-71459: Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary rbac bypass exposes cross-tenant job event tree structure

Published Aug 6, 2026
·
Updated

A flaw was found in automation-controller. The JobJobEventsChildrenSummary view does not declare model or parentmodel attributes, causing ModelAccessPermission.checkgetpermissions() to return True for any authenticated user. An attacker with any valid credential can read job event tree structure and eventprocessingfinished status for arbitrary jobs across all organizations, and enumerate valid job IDs platform-wide via the 200/404 response oracle.

Other sources

JobJobEventsChildrenSummary view has no model/parentmodel. ModelAccessPermission.checkgetpermissions() falls through (returns True) for any authenticated user. The view uses raw getobjector404(Job, pk) without DRF object-level permission check. Zero-privilege user reads event tree structure, eventprocessingfinished status, and enumerates Job IDs platform-wide via 200/404 oracle. Sibling endpoint /jobs/{id}/jobevents/ correctly returns 403.

— MITRE

Affected Software

1 affected component
Red Hat Ansible Automation Controller

Event History

Aug 6, 2026
Data Sourced
via Red Hat·10:55 PM
DescriptionSeverityAffected Software
Sep 23, 2026
CVE Published
via MITRE·06:08 PM
Data Sourced
via MITRE·06:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any authenticated user with a valid credential can exploit it, including a zero-privilege user. The issue permits access across organization boundaries.

2

What information can an attacker obtain?

An attacker can read job event tree structure and the event_processing_finished status for arbitrary jobs. They can also enumerate valid job IDs across the platform by observing whether requests return 200 or 404.

3

Is access to the normal job-events endpoint similarly affected?

No. The sibling endpoint /jobs/{id}/job_events/ correctly returns 403, while the affected JobJobEventsChildrenSummary view does not perform the required object-level permission check.

4

How can I determine whether this endpoint is exposed?

Test the JobJobEventsChildrenSummary endpoint using a low-privilege authenticated account against a job in another organization. A successful response or a 200-versus-404 distinction for arbitrary job IDs indicates the affected authorization behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203