STIGQter STIGQter: STIG Summary: Red Hat Ansible Automation Controller Web Server Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 05 Jan 2026:

All Automation Controller NGINX front-end web servers must not perform user management for hosted applications.

DISA Rule

SV-256946r960963_rule

Vulnerability Number

V-256946

Group Title

SRG-APP-000141-WSR-000015

Rule Version

APWS-AT-000250

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

As a system administrator for each Automation Controller NGINX web server host, navigate to Settings >> Authentication.

Configure the appropriate authentication service.

Check Contents

As a system administrator for each Automation Controller NGINX web server host, navigate to Settings >> Authentication.

Review the configuration and verify that the appropriate authentication service is configured.

If no authentication service is configured, this is a finding.

Vulnerability Number

V-256946

Documentable

False

Rule Version

APWS-AT-000250

Severity Override Guidance

As a system administrator for each Automation Controller NGINX web server host, navigate to Settings >> Authentication.

Review the configuration and verify that the appropriate authentication service is configured.

If no authentication service is configured, this is a finding.

Check Content Reference

M

Target Key

5535