Junglewise Threat Intelligence

CVE-2026-16211: Allegro Ralph race condition in Hostname Allocation Handler

CVE-2026-16211 · Severity: low · CVSS 2.6 · Published 2026-07-19

Executive brief

Allegro Ralph is an asset management and Data Center Infrastructure Management (DCIM) system. A flaw in how the system assigns names to new hardware assets can allow two different devices to be assigned the same hostname simultaneously. This can lead to operational errors, such as automation scripts targeting the wrong server or conflicts in network identity and DNS records.

Technical details

A race condition exists in the `AssetLastHostname.increment_hostname` function within `src/ralph/assets/models/assets.py`. The vulnerability occurs because the application performs an atomic database increment of a counter but follows it with a separate, non-atomic read operation to retrieve the new value. If two workers perform increments nearly simultaneously, both may read the final incremented value, resulting in duplicate hostname generation. An attacker with low-privileged access to trigger asset creation could potentially exploit this timing window, though it is primarily an issue of improper synchronization (CWE-362) during high-concurrency events. As of the advisory date, the project has been notified but a formal patch has not been confirmed.

Affected products

  • Allegro Ralph up to bcf65b994ef29fb3fc2e10b660e6288723d5209e

Timeline

  • 2026-06-13: disclosed: Issue reported on GitHub repository
  • 2026-07-19: advisory: CVE published via VulDB/NVD

References