A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny) over-serializes RBAC-gated automation-mesh data into its anonymous response, exposing the full instance inventory (node hostnames, node types, UUIDs, heartbeats, capacities, and exact versions), all instance-group names and membership, the deployment install UUID, and the active control node. A remote, unauthenticated attacker can use this to map the control plane and fingerprint software versions for targeted attacks. This flaw affects confidentiality only; it does not expose secrets, credentials, or tenant data.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-platform-uiUpgrade automation-eda-controllerUpgrade python3.12-django-ansible-base+authenticationUpgrade receptorUpgrade automation-eda-controller-worker-servicesUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade automation-eda-controller-baseUpgrade aap-metrics-utilityUpgrade python3.12-django-ansible-base+channel_authUpgrade automation-gateway-proxy-server-debuginfoUpgrade python3.12-galaxy-ngUpgrade automation-gateway-serverUpgrade python3.12-django-ansible-base+api_documentationUpgrade python3.12-sqlparseUpgrade receptor-debugsourceUpgrade automation-hubUpgrade automation-gateway-configUpgrade receptorctlUpgrade python3.12-django-ansible-baseUpgrade python3.12-django-ansible-base+resource_registryUpgrade automation-controllerUpgrade automation-controller-uiUpgrade automation-eda-controller-base-servicesUpgrade receptor-debuginfoUpgrade automation-gateway-proxy-debugsourceUpgrade automation-gateway-proxy-serverUpgrade python3-sqlparseUpgrade python3.12-django-ansible-base+rbacUpgrade automation-controller-cliUpgrade python3.12-django-ansible-base+activitystreamUpgrade automation-eda-controller-event-stream-servicesUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-controller-serverUpgrade automation-gateway-proxyUpgrade python3.12-gitpythonUpgrade python3.12-django-ansible-base+redis_clientUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-gatewayUpgrade automation-controller-venv-tower | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub