Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94416— Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery

Quick assessment

Affected
Red Hat Red Hat Ansible Automation Platform 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Ansible Automation Platform (AAP) 网关中发现了一个授权绕过漏洞。该网关 API 允许经过身份验证的管理员为 Controller 服务集群创建新的服务密钥。由于服务密钥的创建并未严格限制在安装程序预置的合法路径中,管理员所颁发的密钥在密码学层面与合法密钥无法区分,攻击者可利用其伪造服务身份验证令牌,从而冒充 Controller 服务。 结合网关的 OIDC 工作负载身份端点(通过配置 启用),攻击者能够驱动网关为任意 Controller 工作负载签名工作负载身份令牌(Wor

CVSS 6.8 · Medium EPSS 0.45% · P37
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94416

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery
Source: CVE Program / CVE List V5
Vulnerability Description
An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will accept the forged WIT and return the AAP credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用欺骗进行的认证绕过
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2
Red Hat Red Hat Ansible Automation Platform 2 - cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2026-94416

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94416

请登录查看更多情报信息。

Other References for CVE-2026-94416 (4)

Same Patch Batch · Red Hat · 2026-09-24 · 8 CVEs total

CVE-2026-90959 8.1 HIGH Pulpcore: pulpcore: file:// scheme allowlist bypass in content upload file_url field enabl
CVE-2026-95521 7.8 HIGH Rpm: rpm: shell command injection via macro expansion of source/spec file basenames when i
CVE-2026-95519 7.8 HIGH Rpm: code execution via macro expansion of manifest entries in `rpmgi` (`-q -p` / verify m
CVE-2026-97185 7.8 HIGH Gimp: gimp: out-of-bounds write in gimpressionist plugin via crafted preset file
CVE-2026-97177 6.6 MEDIUM Keycloak-services: keycloak-services: generic user update bypasses denied reset-password p
CVE-2026-97311 4.3 MEDIUM Keycloak-services: keycloak-services: admin rest api role-groups endpoint discloses groups
CVE-2026-97176 4.2 MEDIUM Keycloak-services: keycloak-services: essential acr requirement silently bypassed via cook

IV. Related Vulnerabilities

V. Comments for CVE-2026-94416

No comments yet


Leave a comment