Foreman Ansible Plugin: Unscoped Host Query Exposes Hidden Parameters
CVE-2026-92893 Published on September 17, 2026
Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters
A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticated user whose host visibility is restricted by a permission filter can supply arbitrary host IDs within their organization and receive the full Ansible inventory for those hosts, including parameter values marked as hidden.
Vulnerability Analysis
CVE-2026-92893 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-92893 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-92893
Want to know whenever a new CVE is published for Red Hat Satellite? stack.watch will email you.