CVE-2026-68562
MEDIUMAnsible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering
Title source: cnaDescription
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
References (2)
Core 2
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-68562
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2466035
https://bugzilla.redhat.com/show_bug.cgi?id=2466035
Scores
CVSS v3
6.2
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
Details
CWE
CWE-610
Status
published
Products (2)
Red Hat/Red Hat Enterprise Linux 10
Red Hat/Red Hat Enterprise Linux 9
Published
Jul 30, 2026
Tracked Since
Jul 31, 2026