CVE-2026-103869
Received Received - Intake

Bearer Token Reuse Flaw in Pulp-Ansible Collection Remotes

Vulnerability report for CVE-2026-103869, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: redhat-SADP

Description

A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat pulp-ansible From 0.6.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-488 The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in pulp-ansible's bearer-token refresh system for Ansible collection remotes. An access token is stored in a shared module-level variable and reused across all token downloads in a worker process. A malicious user who can sync an Ansible remote with token refresh and redirect it to their own server can obtain and reuse an access token meant for a different remote. The token remains valid until the worker process ends.

Detection Guidance

Check pulp-ansible worker processes for improper token reuse by inspecting module-level variables in pulp_ansible/app/downloaders.py. Look for the AUTH_TOKEN global variable being shared across multiple downloaders. Review logs for token refresh events where the same token is used for multiple remotes.

Impact Analysis

If you manage pulp-ansible environments, an attacker with sync permissions could access tokens for other remotes, potentially gaining unauthorized access to services that issued those tokens. This could lead to data exposure or further attacks, though content stored in Pulp remains unchanged and the service is not stopped.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. If tokens grant access to protected health or personal data, their exposure may result in compliance breaches, requiring investigation and potential reporting under these regulations.

Mitigation Strategies

Apply available security updates for pulp-ansible immediately. Avoid syncing Ansible remotes with token refresh to untrusted servers. Monitor network traffic for unauthorized token reuse. Restart pulp-ansible workers to clear any compromised tokens.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103869. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart