Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
223 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.57% | — | Redhat Ansible Automation PlatformAI | 4/5/2026 | 26/8/2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or… | |
| Pendiente de análisis | Media (5.3) | 0.41% | — | Redhat Ansible Automation PlatformAI | 17/4/2026 | 17/6/2026 | A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly sanitized before being written to logs, allowing the attacker to inject control characters such as… | |
| Modificada | Media (6.4) | 0.18% | — | Redhat Ansible Automation Platform | 8/4/2026 | 24/9/2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within an affected container, even as a non-root… | |
| Analizada | Media (6.7) | 0.17% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to… | |
| Analizada | Media (6.7) | 0.20% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By… | |
| Analizada | Media (6.7) | 0.17% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of… | |
| Aplazada | Media (4.2) | 0.25% | — | Ansible LightspeedAI | 6/2/2026 | 17/6/2026 | A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the authenticated user making the request. As a result, an attacker with valid credentials could access or influence… | |
| Aplazada | Alta (8.5) | 0.42% | — | Redhat Ansible Automation PlatformAI | 8/1/2026 | 17/6/2026 | A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were… | |
| Aplazada | Media (5.3) | 0.27% | — | Ansible Aap-gatewayAI | 4/8/2025 | 17/6/2026 | A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda. | |
| Aplazada | Media (4.4) | 0.22% | — | Ansible Automation PlatformAI | 31/7/2025 | 17/6/2026 | A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurations. While access is limited to privileged users, the clear text… | |
| Analizada | Baja (3.5) | 0.19% | — | Redhat Ansible Automation Platform | 11/7/2025 | 17/6/2026 | A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information. | |
| Analizada | Baja (3.1) | 0.11% | — | Redhat Ansible Automation Platform | 11/7/2025 | 17/6/2026 | A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data. | |
| Aplazada | Alta (8.8) | 0.58% | — | Redhat Ansible Automation PlatformAI | 30/6/2025 | 17/6/2026 | A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on the EDA worker. In OpenShift, it can lead… | |
| Aplazada | Alta (8.8) | 0.61% | — | Redhat Ansible Automation PlatformAIRedhat EDAAI | 30/6/2025 | 17/6/2026 | A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments and execute arbitrary commands on the EDA worker. In Kubernetes/OpenShift environments, this can lead… | |
| Aplazada | Media (6.5) | 0.41% | — | Redhat Ansible Automation PlatformAIRedhat Event Driven AnsibleAIRedhat Event StreamsAI | 28/3/2025 | 17/6/2026 | A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This issue exists for any "debug" action in a rulebook and also affects Event Streams. | |
| Aplazada | Alta (8.1) | 0.33% | — | Ansible Aap-gatewayAI | 3/3/2025 | 17/6/2026 | A flaw was found in the Ansible aap-gateway. Concurrent requests handled by the gateway grpc service can result in concurrency issues due to race condition requests against the proxy. This issue potentially allows a less privileged user to obtain the JWT of a greater privileged user, enabling the server to be… | |
| Aplazada | Media (5) | 0.53% | — | Ansible Automation PlatformAI | 25/11/2024 | 17/6/2026 | A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth2_provider for OAuth2 authentication. While the impact is… | |
| Aplazada | Media (5.5) | 0.50% | — | Ansible-coreAI | 12/11/2024 | 30/6/2026 | A flaw was found in Ansible-Core. This vulnerability allows attackers to bypass unsafe content protections using the hostvars object to reference and execute templated content. This issue can lead to arbitrary code execution if remote data or module outputs are improperly templated within playbooks. | |
| Aplazada | Media (6.3) | 0.26% | 💥 PoC | Ansible-coreAI | 6/11/2024 | 17/6/2026 | A flaw was found in Ansible. The ansible-core `user` module can allow an unprivileged user to silently create or replace the contents of any file on any system path and take ownership of it when a privileged user executes the `user` module against the unprivileged user's home directory. If the unprivileged user has… | |
| Modificada | Media (6.1) | 0.40% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 16/10/2024 | 17/6/2026 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a URL, which can lead to redirecting, injecting malicious script, stealing sessions and data. | |
| Aplazada | Media (5.3) | 0.16% | — | Redhat Ansible Automation PlatformAIRedhat Event Driven AutomationAI | 8/10/2024 | 17/6/2026 | A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this vulnerability by sniffing the plaintext data transmitted between the EDA and AAP. An attacker with system access could exploit this… | |
| Aplazada | Media (5.5) | 0.27% | — | AnsibleAI | 14/9/2024 | 17/9/2026 | A flaw was found in Ansible, where sensitive information stored in Ansible Vault files can be exposed in plaintext during the execution of a playbook. This occurs when using tasks such as include_vars to load vaulted variables without setting the no_log: true parameter, resulting in sensitive data being printed in the… | |
| Aplazada | Media (6.6) | 0.43% | — | Ansible Automation ControllerAI | 12/9/2024 | 17/6/2026 | An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account. | |
| Aplazada | Alta (8.2) | 0.40% | — | Ansibleguy-webuiAI | 28/5/2024 | 17/6/2026 | ansibleguy-webui is an open source WebUI for using Ansible. Multiple forms in versions < 0.0.21 allowed injection of HTML elements. These are returned to the user after executing job actions and thus evaluated by the browser. These issues have been addressed in version 0.0.21 (0.0.21.post2 on pypi). Users are advised… | |
| Aplazada | Alta (8.1) | 0.38% | — | Ansible Automation PlatformAIAnsible Rulebook EDA ServerAI | 25/4/2024 | 17/6/2026 | A flaw was found in the ansible automation platform. An insecure WebSocket connection was being used in installation from the Ansible rulebook EDA server. An attacker that has access to any machine in the CIDR block could download all rulebook data from the WebSocket, resulting in loss of confidentiality and integrity… |