« Volver al listado

Redhat

Redhat AWX: vulnerabilidades y CVE

Redhat AWX tiene 7 vulnerabilidades publicadas, 7 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses7
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-75884Crítica (9.1)0.41%—23 sept 2026
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and…
CVE-2026-76648Alta (8.5)0.24%—23 sept 2026
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with…
CVE-2026-71366Alta (7.7)0.56%—24 ago 2026
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP…
CVE-2026-71364Alta (7.2)1.7%—24 ago 2026
A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without…
CVE-2026-71365Alta (7.7)0.49%—18 ago 2026
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url)…
CVE-2026-16544Media (6.5)0.39%—22 jul 2026
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events).…
CVE-2026-12726Media (6.3)0.33%—19 jun 2026
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services5
  2. T1090 Proxy2
  3. T1078 Valid Accounts1
  4. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Redhat