« Back to list

Redhat

Redhat AWX: vulnerabilities and CVEs

Redhat AWX has 7 published vulnerabilities, 7 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs7
Last 12 months7
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-75884Critical (9.1)0.41%—Sep 23, 2026
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and…
CVE-2026-76648High (8.5)0.24%—Sep 23, 2026
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with…
CVE-2026-71366High (7.7)0.56%—Aug 24, 2026
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP…
CVE-2026-71364High (7.2)1.7%—Aug 24, 2026
A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without…
CVE-2026-71365High (7.7)0.49%—Aug 18, 2026
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url)…
CVE-2026-16544Medium (6.5)0.39%—Jul 22, 2026
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events).…
CVE-2026-12726Medium (6.3)0.33%—Jun 19, 2026
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points…

Other products by Redhat