When a user enabled Release Automation for an Automation Engine (AE) client on an affected release, the system created the AE administrator account for that client using fixed, undisclosed credentials instead of operator-chosen values.
Because the password was never displayed in the user interface, operators had no indication that a shared, static password had been set. Consequently, the password could not be recorded, changed, or rotated through the normal workflow at the time the client was created.
Security: Every client enabled for Release Automation on an affected release received the same predictable administrator username and password.
Scope: This issue only affects clients that were enabled for Release Automation while running an affected release. Clients enabled on a version that includes the fix are not affected.
Automic Continuous Delivery Automation 26.1.0
The client-enablement workflow constructed the administrator account request using a hardcoded username/password pair instead of credentials supplied by the operator. This was an implementation defect, not a configuration issue—no customer action caused this condition.
This has been corrected. The client-enablement screen now requires the operator to explicitly enter and confirm an administrator username and password as part of enabling Release Automation for a client; no fixed or hidden credentials are sent to the backend. The fix is available as of Automic Continuous Delivery Automation 26.1.0.
When Release Automation was enabled for one or more AE clients on an affected release, the system may have created the corresponding administrator account using fixed (default) credentials rather than a user-defined password.
To ensure your environment is secure and properly configured, please take the following steps:
Upgrade: Update your system to a release version that contains the fix for this credential issue.
Review Client Configurations: Once the upgrade is complete, review the administrator account credentials for all AE clients currently enabled for Release Automation.
Contact Support: Contact Broadcom Automic Support and reference article ID DE198119 if you have questions about whether a specific environment is affected or if you need assistance applying the fix.