CVE-2026-68562 Details
Description
A flaw was found in ansible-collection-redhat-leapp. An attacker with privileged write access to a managed node's Leapp report content can manipulate it. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read its own local files and copy them to the managed node. This vulnerability leads to information disclosure, potentially exposing sensitive controller-side data such as private keys or credentials.
A vulnerability exists in the Red Hat Ansible Collection Leapp. It allows an attacker with privileged write access to a managed node's Leapp report to manipulate the report content. When an operator executes a specific remediation task, this altered report can prompt the Ansible controller to access local files and transfer them to the managed node. This issue could lead to unauthorized disclosure of sensitive data from the controller, such as private keys or credentials.
Avoid running the 'leapp_corrupted_grubenv_file' remediation on managed nodes with untrusted Leapp report content. If the remediation must be applied, adjust the Ansible playbook to set 'remote_src: true' for 'ansible.builtin.copy' tasks within the 'leapp_corrupted_grubenv_file' role, and validate that 'src' paths are limited to the '/boot' directory. These changes will take effect the next time the Ansible playbook is executed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-68562 | [email protected] | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2466035 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-610 | Externally Controlled Reference to a Resource in Another Sphere | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |