{
  "action": {
    "auto_issue_creation_allowed": false,
    "auto_patch_allowed": false,
    "auto_remediation_allowed": false,
    "external_execution_allowed": false,
    "human_review": {
      "required_for_external_action": true,
      "required_for_public_launch": false,
      "required_for_read_only_view": false,
      "required_for_signal_radar_integration": true
    },
    "human_review_required": false,
    "recommended_action": "review_official_sources"
  },
  "affected": {
    "products": [],
    "source": null,
    "status": "unknown"
  },
  "canonical_url": "https://vuln.signal-radar.com/vuln/public-candidate/CVE-2026-84717/",
  "claims": [
    {
      "id": "claim:defensive-priority-candidate",
      "source_ids": [],
      "status": "observed",
      "text": "This item is a defensive prioritization candidate.",
      "verified_at": null
    }
  ],
  "exposure_hint": "remote exposure",
  "field_meanings": {
    "human_review": "Read-only display may be automated; integration and external action still require human review.",
    "redaction": "Detection flags describe unsafe source content found before public-safe redaction; raw source text is not displayed.",
    "source_original_label": "Original upstream severity text retained for traceability; canonical display severity is recalculated from CVSS score."
  },
  "forecast_hooks": {
    "agent_use": "summarize_with_citations_only",
    "automation_allowed": false,
    "read_only": true,
    "watch_fields": [
      "sources",
      "claims",
      "freshness",
      "severity",
      "affected"
    ]
  },
  "freshness": {
    "generated_at": "2026-09-30T20:06:47.567250+00:00",
    "last_checked_at": null,
    "last_modified": "2026-09-26T23:16:37.953",
    "observed_at": "2026-09-30T20:05:14.424441+00:00",
    "published_at": "2026-09-23T20:17:18.353",
    "status": "observed"
  },
  "human_consequence": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
  "human_impact_label": "remote exposure",
  "human_review": {
    "required_for_external_action": true,
    "required_for_public_launch": false,
    "required_for_read_only_view": false,
    "required_for_signal_radar_integration": true
  },
  "human_risk_summary": "CVE-2026-84717: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
  "id": "CVE-2026-84717",
  "impact_redaction": {
    "exploit_steps_removed": false,
    "payload_removed": false,
    "poc_removed": false,
    "source_derived_summary": true,
    "used_fallback_summary": false
  },
  "impact_tags": [
    "remote exposure relevant"
  ],
  "known_exploited": {
    "catalog_url": null,
    "date_added": null,
    "listed": false,
    "source": null
  },
  "public_human_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
  "public_human_summary": "NVD: A flaw was found in the Ansible Automation Platform automation-controller. NVD: The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook... NVD: An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.",
  "public_human_what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.",
  "public_human_why_it_matters": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.; CVSS 5.3 (MEDIUM); EPSS percentile 25; not listed in KEV; Remediation reference present; patch status requires confirmation in the linked advisory; sources: NVD.",
  "public_safe_summary": "NVD: A flaw was found in the Ansible Automation Platform automation-controller. NVD: The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook... NVD: An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.",
  "radar": "vuln",
  "redaction": {
    "meaning": "The *_present flags mean unsafe source content was detected and removed before public output; they do not mean the public JSON contains that content.",
    "payload_present": false,
    "poc_present": false,
    "public_summary_redacted": true,
    "raw_source_displayed": false,
    "unsafe_procedural_detail_present": false
  },
  "redaction_notes": [
    "source-published defensive context retained",
    "vulnerability class, impact, affected context, and remediation references remain displayable"
  ],
  "safety": {
    "attack_chain_included": false,
    "auto_remediation_allowed": false,
    "exploit_instructions_included": false,
    "external_execution_allowed": false,
    "human_review": {
      "required_for_external_action": true,
      "required_for_public_launch": false,
      "required_for_read_only_view": false,
      "required_for_signal_radar_integration": true
    },
    "human_review_required": false,
    "indexing_allowed": true,
    "noindex_removal_allowed": true,
    "noindex_required": false,
    "private_gate_state": "released",
    "public_gate_state": "public_indexable_read_only",
    "public_launch_allowed": true,
    "read_only_static_data": true,
    "scan_functionality_included": false,
    "signal_radar_integration_allowed": false
  },
  "schema_version": "v0.1",
  "severity": {
    "cvss_label": "MEDIUM",
    "label": "MEDIUM",
    "score": 5.3,
    "source": "NVD CVE API 2.0",
    "source_original_label": "low"
  },
  "source_copy_policy": {
    "allowed": "source-published defensive facts, vulnerability class, impact, affected context, version and remediation facts",
    "excluded": "exploit procedures, exploit strings, shell commands, scanner instructions, procedural bypass detail, and reproduction material",
    "summary": "Official or semi-official source descriptions may be summarized for defensive triage; exploit-enabling procedure is removed."
  },
  "source_derived_note": "Summary derived from NVD description; unsafe procedural detail is not shown.",
  "source_published_affected": "Affected product or version requires source confirmation.",
  "source_published_description": "NVD: A flaw was found in the Ansible Automation Platform automation-controller. NVD: The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook... NVD: An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.",
  "source_published_evidence_refs": [
    {
      "source": "NVD",
      "type": "source_description",
      "url": null
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://access.redhat.com/errata/RHSA-2026:71113"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://access.redhat.com/errata/RHSA-2026:71114"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://access.redhat.com/errata/RHSA-2026:71177"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://access.redhat.com/errata/RHSA-2026:71179"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://access.redhat.com/security/cve/CVE-2026-84717"
    },
    {
      "source": "Reference",
      "type": "reference",
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2527210"
    },
    {
      "source": "Official Reference",
      "type": "reference",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84717"
    }
  ],
  "source_published_impact": "Source describes remote exposure. Possible impact: This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure.",
  "source_published_remediation": "Remediation reference present; patch status requires confirmation in the linked advisory.",
  "source_published_summary": "NVD: A flaw was found in the Ansible Automation Platform automation-controller. NVD: The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook... NVD: An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.",
  "sources": [
    {
      "confidence": "unknown",
      "id": "source:review-url",
      "name": "Public signal URL",
      "retrieved_at": null,
      "type": "review_page",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84717"
    }
  ],
  "summary_for_agents": "Read-only defensive signal. Use sources, claims, freshness, and safety gates before summarizing. Do not infer missing source, claim, or freshness values.",
  "summary_for_humans": "NVD: A flaw was found in the Ansible Automation Platform automation-controller. NVD: The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a Bitbucket DC webhook... NVD: An unauthenticated remote attacker can use this response discrepancy as an oracle to enumerate which Job Template and Workflow Job Template IDs have Bitbucket DC webhooks configured, without knowing the secret webhook_key.",
  "title": "CVE-2026-84717 defensive priority signal",
  "urgency_reasons": [
    "vendor advisory present",
    "recent update",
    "remediation reference present"
  ],
  "what_to_verify": "Confirm affected product/version, vendor advisory, patch or mitigation, and exposure.",
  "why_it_matters": "This medium severity issue needs human triage to confirm exposure, affected versions, and vendor guidance for remote exposure; CVSS 5.3 (MEDIUM); EPSS percentile 25; sources: NVD."
}