Redhat
Redhat Ansible Automation Platform: vulnerabilidades y CVE
Redhat Ansible Automation Platform tiene 48 vulnerabilidades publicadas, 24 de ellas en los últimos 12 meses. 4 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses24
Críticas4
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48710 | Media (6.5) | 7.1% | ⚠ Explotación activa | 26 may 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw… |
| CVE-2023-44487 | Alta (7.5) | 100% | ⚠ Explotación activa | 10 oct 2023 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94416 | Media (6.8) | 0.45% | — | 24 sept 2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because… |
| CVE-2026-84724 | Media (6.6) | 0.29% | — | 23 sept 2026 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job template launch endpoint stores a user-supplied "days" variable without running the… |
| CVE-2026-84706 | Alta (7.6) | 0.31% | — | 23 sept 2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed… |
| CVE-2026-84691 | Alta (8.7) | 0.20% | — | 23 sept 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API 4XX errors is an administrator-controlled Python format-string template that is… |
| CVE-2026-84683 | Alta (8.7) | 0.26% | — | 23 sept 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not… |
| CVE-2026-75884 | Crítica (9.1) | 0.41% | — | 23 sept 2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and… |
| CVE-2026-84502 | Crítica (9.9) | 0.62% | — | 23 sept 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module.… |
| CVE-2026-84499 | Alta (7.7) | 0.38% | — | 23 sept 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or… |
| CVE-2026-84486 | Alta (8.2) | 0.52% | — | 23 sept 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including… |
| CVE-2026-84474 | Crítica (9.9) | 0.80% | — | 23 sept 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in… |
| CVE-2026-71462 | Media (4.1) | 0.26% | — | 23 sept 2026 | — |
| CVE-2026-84470 | Media (6.4) | 0.30% | — | 1 sept 2026 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check,… |
| CVE-2026-12564 | Crítica (9.6) | 0.35% | — | 18 ago 2026 | A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends… |
| CVE-2026-18141 | Alta (8.2) | 0.43% | — | 31 jul 2026 | A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event… |
| CVE-2026-44495 | Alta (7.7) | 1.0% | — | 11 jun 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same… |
| CVE-2026-46625 | Alta (7.5) | 0.99% | — | 10 jun 2026 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is… |
| CVE-2026-48710 | Media (6.5) | 7.1% | ⚠ Explotación activa | 26 may 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw… |
| CVE-2026-6266 | Alta (8.3) | 0.57% | — | 4 may 2026 | A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without… |
| CVE-2026-6494 | Media (5.3) | 0.41% | — | 17 abr 2026 | A flaw was found in the AAP MCP server. An unauthenticated remote attacker can exploit a log injection vulnerability by sending specially crafted input to the `toolsetroute` parameter. This parameter is not properly… |
| CVE-2025-57847 | Media (6.4) | 0.18% | — | 8 abr 2026 | A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In… |
| CVE-2025-9909 | Media (6.7) | 0.17% | — | 27 feb 2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the… |
| CVE-2025-9908 | Media (6.7) | 0.20% | — | 27 feb 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as… |
| CVE-2025-9907 | Media (6.7) | 0.17% | — | 27 feb 2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the… |
| CVE-2025-14025 | Alta (8.5) | 0.42% | — | 8 ene 2026 | A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to… |
| CVE-2025-53862 | Baja (3.5) | 0.19% | — | 11 jul 2025 | A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information. |
| CVE-2025-53861 | Baja (3.1) | 0.11% | — | 11 jul 2025 | A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data. |
| CVE-2025-49521 | Alta (8.8) | 0.58% | — | 30 jun 2025 | A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject… |
| CVE-2025-49520 | Alta (8.8) | 0.61% | — | 30 jun 2025 | A flaw was found in Ansible Automation Platform’s EDA component where user-supplied Git URLs are passed unsanitized to the git ls-remote command. This vulnerability allows an authenticated attacker to inject arguments… |
| CVE-2025-2877 | Media (6.5) | 0.41% | — | 28 mar 2025 | A flaw was found in the Ansible Automation Platform's Event-Driven Ansible. In configurations where verbosity is set to "debug", inventory passwords are exposed in plain text when starting a rulebook activation. This… |
| CVE-2024-10033 | Media (6.1) | 0.40% | — | 16 oct 2024 | A vulnerability was found in aap-gateway. A Cross-site Scripting (XSS) vulnerability exists in the gateway component. This flaw allows a malicious user to perform actions that impact users by using the "?next=" in a… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Redhat
Enterprise Linux · 1937Enterprise Linux Desktop · 1928Enterprise Linux Server · 1891Enterprise Linux Workstation · 1845Enterprise Linux Server AUS · 1059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 239Linux · 230