Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12726— Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Red Hat Ansible Automation Platform 2是美国Red Hat公司的一款构建、部署和管理自动化的软件。 Red Hat Ansible Automation Platform 2存在安全漏洞,该漏洞源于AWX GitHub webhook集成在处理GitHub pull_request webhooks时,未验证pull_request.statuses_url值是否指向受信任的GitHub API端点,可能导致攻击者提交使用作业模板webhook_key正确签名的伪造we

CVSS 6.3 · Medium EPSS 0.33% · P23

Affected Version Matrix 3

VendorProduct Version RangeStatus
Red Hat Red Hat Ansible Automation Platform 2 any affected
any affected
any affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12726

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller stores the pull_request.statuses_url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged webhook using the job template's webhook_key can redirect the callback to an attacker-controlled URL and exfiltrate the configured GitHub PAT.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
Red Hat Ansible Automation Platform 2 服务端请求伪造漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat Ansible Automation Platform 2是美国Red Hat公司的一款构建、部署和管理自动化的软件。 Red Hat Ansible Automation Platform 2存在安全漏洞,该漏洞源于AWX GitHub webhook集成在处理GitHub pull_request webhooks时,未验证pull_request.statuses_url值是否指向受信任的GitHub API端点,可能导致攻击者提交使用作业模板webhook_key正确签名的伪造we
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2026-12726

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12726

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12726 (1)

Other References for CVE-2026-12726 (1)

Same Patch Batch · Red Hat · 2026-06-19 · 6 CVEs total

CVE-2026-56208 7.6 HIGH Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode
CVE-2026-56209 7.1 HIGH Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map p
CVE-2026-56210 7.1 HIGH Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id
CVE-2026-56211 7.1 HIGH Libaom: libaom: remote code execution via svc layer context handling with attacker-control
CVE-2026-12706 6.5 MEDIUM Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()

IV. Related Vulnerabilities

V. Comments for CVE-2026-12726

No comments yet


Leave a comment