Medium severity6.5NVD Advisory· Published Oct 7, 2026· Updated Oct 7, 2026
CVE-2026-103869
CVE-2026-103869
Description
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.