VYPR
Moderate severity4.1NVD Advisory· Published Sep 23, 2026

automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automation Hub API token

CVE-2026-84680

Description

automation-controller: automation-controller-container: automation-controller: organization galaxy credential attachment checks only read permission on the credential, allowing an organization admin with read-only visibility to bind and server-side-use another tenant's Automation Hub API token

Affected products

1

Patches

Vulnerability mechanics

News mentions

0

No linked articles in our index yet.