{"id":"CVE-2026-84499","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-84499","summary":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Survey questions of type password are write-only and stored\nencrypted, displayed only as a placeholder…","details":"A flaw was found in Red Hat Ansible Automation Platform's automation-\ncontroller. Survey questions of type password are write-only and stored\nencrypted, displayed only as a placeholder on read. When a schedule or\nworkflow job template node is revalidated against a tightened survey\nspecification, the controller decrypts the stored password and includes its\nplaintext value in the minimum/maximum length validation error message\nreturned in the HTTP response. A user with the delegated JobTemplate Admin\nrole can tighten the survey length constraint and trigger revalidation of a\nschedule or node created by another, higher-privileged user, thereby\nrecovering that user's stored password in plaintext.","published":"2026-09-23T19:19:40.233","modified":"2026-09-24T07:16:33.740","cvss":{"score":7.7,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:71113"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:71114"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:71177"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:71179"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-84499"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527090"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-24T07:16:33.740"}}