CVE-2026-71462
StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 resp
CVSS
4.1
Medio
EPSS
0.3%
p15
KEV
—
Exploit Today
5
0-100
Publicado: 23 sept 2026 · Última mod.: 24 sept 2026 · CWE-204
0.3%EPSS · 30 días0.3%
2026-09-242026-09-25
StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant superuser can confirm /etc/tower/SECRET_KEY, k8s service-account token, receptor sockets, ConfigMap mount points. Mainly impactful on managed AAP (ansiblecloud.com) where tenant admin != host admin.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71113
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71114
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71177
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71179
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-71462
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2512371
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-847175.3 MED24.4%
——7A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated
Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping
events after it has already looked up the target template, causing the endpoint to return HTTP
200 for a template that has a Bitbucket DC webhook configured and HTTP 403 otherwise. An
unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate
which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without
knowing the secret webhook_key.1dCVE-2026-714585.0 MED20.5%
——6URLModificationMiddleware resolves named-URL lookups
against unfiltered Model.objects before RBAC. The 403→404
shim only rewrites 403 responses, leaving the pk=0 miss
path with a different 404 detail string. Differential
"Not found." vs "No <Model> matches..." reveals whether
a named resource (org, credential, inventory, host) exists
anywhere on the platform. Enables cross-tenant internal
hostname enumeration.2dCVE-2026-891735.3 MED35.3%
——11Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses.14dCVE-2026-91615.3 MED23.4%
——7Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting.
This issue affects Website Template: through 10092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.15dCVE-2026-867586.5 MED32.7%
——10Snipe-IT before 8.7.0 fails to properly enforce the viewKeys authorization gate in CSV export and API index endpoints, allowing authenticated users with only licenses.view permission to access product keys. Attackers can download all license keys in bulk via CSV export or validate candidate keys through API response discrepancies without needing the viewKeys permission.9dCVE-2026-192057.5 ALT14.0%
——4Observable response discrepancy vulnerability in GastroMenum GastroMenum Web Panel allows Account Footprinting.
This issue affects GastroMenum Web Panel: before 31.08.2026.17d