Redhat
Redhat AWX: vulnerabilities and CVEs
Redhat AWX has 7 published vulnerabilities, 7 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months7
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75884 | Critical (9.1) | 0.41% | — | Sep 23, 2026 | A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and… |
| CVE-2026-76648 | High (8.5) | 0.24% | — | Sep 23, 2026 | CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with… |
| CVE-2026-71366 | High (7.7) | 0.56% | — | Aug 24, 2026 | A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP… |
| CVE-2026-71364 | High (7.2) | 1.7% | — | Aug 24, 2026 | A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without… |
| CVE-2026-71365 | High (7.7) | 0.49% | — | Aug 18, 2026 | A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url)… |
| CVE-2026-16544 | Medium (6.5) | 0.39% | — | Jul 22, 2026 | A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events).… |
| CVE-2026-12726 | Medium (6.3) | 0.33% | — | Jun 19, 2026 | A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points… |
Other products by Redhat
Enterprise Linux · 1,937Enterprise Linux Desktop · 1,928Enterprise Linux Server · 1,891Enterprise Linux Workstation · 1,845Enterprise Linux Server AUS · 1,059Enterprise Linux EUS · 787Enterprise Linux Server TUS · 768Enterprise Linux Server EUS · 622Openshift Container Platform · 328Jboss Enterprise Application Platform · 244Satellite · 238Linux · 230