What is CVE-2026-68562?
CVE-2026-68562 is a flaw in ansible-collection-redhat-leapp where an attacker with privileged write access can manipulate Leapp report content on a managed node. When an operator runs a specific remediation task, this manipulated report can cause the Ansible controller to read and potentially copy its own local files. Systems using this collection should apply patches and review access controls immediately.
Azərbaycanca: CVE-2026-68562, ansible-collection-redhat-leapp kolleksiyasında imtiyazlı yazma girişi olan təcavüzkarın idarə olunan qovşaqdakı Leapp hesabat məzmununu manipulyasiya etməsinə imkan verən zəiflikdir. Operator xüsusi remediation task icra etdikdə, bu manipulyasiya Ansible controller-in öz lokal fayllarını oxumasına və kopyalamasına səbəb ola bilər. Bu kolleksiyadan istifadə edən sistemlərdə dərhal giriş nəzarətləri yoxlanmalı və yamaq tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What is the prerequisite an attacker must meet to exploit CVE-2026-68562?
The attacker must have privileged write access on the managed node.
What is the primary component affected when this vulnerability is exploited?
The primary component affected is the Ansible controller, as it can read and potentially copy its own local files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.