CVE-2026-103869
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 07, 2026
Vendor
unknown
Description
A flaw was found in pulp-ansible's bearer-token refresh for collection remotes. The access token is kept in one module-level variable and reused for every token download in that worker. A user who can sync an Ansible remote that uses token refresh, and can point that remote at a server they control, receives an access token obtained for a different remote, and can reuse it at the service that issued it. Content stored in Pulp is not changed, and the service is not stopped.