REDHAT-BUG-2527090: Medium severity Ansible automation-controller (AWX) vulnerability

Published Sep 1, 2026
·
Updated

A flaw was found in automation-controller (AWX). Write-only survey password values stored on Schedules and WorkflowJobTemplateNodes are encrypted at rest and masked as $encrypted$ on read. LaunchConfigurationBaseSerializer.validate (awx/api/serializers.py) replaces an incoming $encrypted$ with the stored DB ciphertext and revalidates prompts against the job template's current surveyspec; SurveyJobTemplateMixin.acceptorignorevariables (awx/main/models/mixins.py) decrypts the stored password before validation, and surveyelementvalidation interpolates the decrypted plaintext into the "value ... is too small/too large" min/max error for text/textarea/password questions. The error dict is returned verbatim as the HTTP 400 body. A user holding only the delegated JobTemplate Admin role can POST a tightened surveyspec (e.g. "max":1) and then PATCH a schedule of that job template -- either echoing $encrypted$ for the variable, or simply re-stating unifiedjobtemplate to force full-prompt revalidation without knowing the variable name (serializers.py forces full revalidation when unifiedjobtemplate is present) -- and read the stored plaintext password of a schedule created by a different, higher-privileged user (ScheduleAccess.canchange grants a JT admin write on all schedules of the template regardless of creator). The same base serializer backs WorkflowJobTemplateNodeSerializer, so workflow nodes are equally affected. Discovered internally; verified live on AAP 2.7 / automation-controller 4.8.1; still present on devel. Upstream: github.com/ansible/awx (api/serializers.py LaunchConfigurationBaseSerializer; main/models/mixins.py surveyelementvalidation / acceptorignorevariables; main/access.py ScheduleAccess.canchange)

Affected Software

1 affected component
Ansible automation-controller (AWX)=4.8.1

Event History

Sep 1, 2026
Data Sourced
via Red Hat·08:55 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What level of access does an attacker need?

The attacker needs the delegated JobTemplate Admin role. They must be able to modify the job template survey specification and PATCH a schedule associated with that job template.

2

Which stored secrets can be exposed?

The affected values are write-only survey password values stored on Schedules and WorkflowJobTemplateNodes. The plaintext can be returned in an HTTP 400 validation error when the stored value fails a tightened minimum or maximum validation constraint.

3

Does the attacker need to know the password variable name or its current value?

No. They can echo the masked "$encrypted$" value, or re-state unified_job_template to force full prompt revalidation without knowing the variable name. The server retrieves and decrypts the stored value during validation.

4

How is the secret disclosed to the attacker?

The decrypted plaintext is interpolated into a survey validation error such as a value being too small or too large. That error dictionary is returned verbatim in the HTTP 400 response body.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203