Red HatCVE-2026-68562
ansible-collection-redhat-leapp: information disclosure
Medium6.2CVE-2026-68562 · Published Jul 30, 2026 · updated Aug 3, 2026
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-610
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 30 | ansible-collection-redhat-leapp.: insecure permissions | Medium5.5 | No fix yet |
| Jul 30 | Red Hat Samba: out-of-bounds read | Medium5.3 | No fix yet |
| Jul 30 | Red Hat Enterprise Linux 10: improper authorization | High8.8 | No fix yet |
| Jul 30 | Red Hat Samba: denial of service | Medium5.3 | No fix yet |
| Jul 30 | Red Hat Cost Management Metrics Operator: server-side request forgery | High7.6 | No fix yet |
| Jul 30 | Red Hat Cost Management Metrics Operator: server-side request forgery | High7.6 | No fix yet |