{"id":"CVE-2026-84720","published":"2026-09-23T20:17:18.753","lastModified":"2026-09-24T15:17:45.170","description":"A flaw was found in the Ansible Automation Platform automation-controller. The\nWorkflowJobNode.ancestor_artifacts database column, which stores the raw merged set_stats\nartifacts propagated between workflow nodes, is not wrapped in prevent_search() and is therefore\naccepted for arbitrary field lookups by the REST filter backend, even though it is omitted from\nthe API serializer. Because the column is persisted before Ansible's no_log masking is applied,\na user with only read access to a workflow — or, via a regular-expression lookup that bypasses\nthe JSON cross-relation filter guard through the world-readable credential-types endpoint, any\nauthenticated user with no roles — can use the result count as a boolean/count oracle to recover,\ncharacter by character, secret values that a playbook author explicitly marked no_log, including\nacross organizations.","cvssScore":6.5,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-639"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:71113","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71114","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71177","tags":[]},{"url":"https://access.redhat.com/errata/RHSA-2026:71179","tags":[]},{"url":"https://access.redhat.com/security/cve/CVE-2026-84720","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2527214","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}