Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in Red Hat Ansible Automation Platform 2.5 for RHEL 8, with AI-generated Chinese analysis, references, and POCs.

This page details security vulnerabilities affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8, categorized by Common Weakness Enumeration classifications. It aggregates a comprehensive list of identified flaws, including remote code execution, privilege escalation, and information disclosure issues, covering advisories published from 2023 through the present. This collection serves as a centralized resource for administrators and security analysts to monitor the security posture of this specific enterprise automation solution. Users can track vendor security advisories to stay informed about newly disclosed risks and remediation steps. The page also allows for a deeper understanding of specific weakness classes relevant to the platform, such as improper access controls or injection flaws, providing context on how these vulnerabilities typically manifest in Ansible-based environments. Additionally, it offers a historical view of the product’s vulnerability landscape, enabling teams to analyze trends and prioritize patching efforts based on severity and exploitability. By consolidating this data, the page facilitates efficient risk management and compliance auditing for organizations relying on Red Hat Ansible Automation Platform. The information is structured to help IT professionals quickly identify affected components and evaluate the potential impact on their infrastructure without needing to navigate multiple disparate sources. This streamlined approach supports proactive security maintenance and ensures that critical updates are applied promptly to mitigate known threats within the RHEL 8 ecosystem.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2026-84724 Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process CWE-88 6.6 Medium 2026-09-23
CVE-2026-84720 Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle CWE-639 6.5 Medium 2026-09-23
CVE-2026-84718 Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust CWE-348 4.3 Medium 2026-09-23
CVE-2026-84717 Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates CWE-204 5.3 Medium 2026-09-23
CVE-2026-84716 Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames CWE-266 6.6 Medium 2026-09-23
CVE-2026-84712 Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership CWE-497 5.3 Medium 2026-09-23
CVE-2026-84714 Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment CWE-184 7.1 High 2026-09-23
CVE-2026-84706 Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment CWE-184 7.6 High 2026-09-23
CVE-2026-84691 Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator CWE-134 8.7 High 2026-09-23
CVE-2026-84683 Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover CWE-79 8.7 High 2026-09-23
CVE-2026-84499 Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message CWE-209 7.7 High 2026-09-23
CVE-2026-71465 Automation-controller: automation-controller-container: automation-controller: ad-hoc command limit field allows cli argument injection into ansible executable CWE-88 3.1 Low 2026-09-23
CVE-2026-71464 Automation-controller: automation-controller-container: automation-controller: schedule and workflowjobtemplatenode scm_branch prompt bypasses leading-dash git-argument guard CWE-88 3.1 Low 2026-09-23
CVE-2026-71463 Automation-controller: automation-controller-container: automation-controller: notification template jinja whitelist bypass via conditional gating leaks tracebacks CWE-209 2.7 Low 2026-09-23
CVE-2026-71462 Automation-controller: automation-controller-container: automation-controller: custom_venv_path setting provides filesystem path-existence oracle on control pod CWE-204 4.1 Medium 2026-09-23
CVE-2026-71460 Automation-controller: automation-controller-container: automation-controller: any authenticated user reads red hat subscription/license details via /config/ CWE-862 4.3 Medium 2026-09-23
CVE-2026-71459 Automation-controller: automation-controller-container: automation-controller: jobjobeventschildrensummary rbac bypass exposes cross-tenant job event tree structure CWE-862 5.0 Medium 2026-09-23
CVE-2026-71458 Automation-controller: automation-controller-container: automation-controller: named-url 404 body oracle enables cross-tenant resource name enumeration CWE-204 5.0 Medium 2026-09-23
CVE-2026-84470 Automation-controller: automation-controller-container: automation-controller/awx: bulk job launch checks instance_groups at read level instead of use level, allowing execution-placement authorization bypass CWE-862 6.4 Medium 2026-09-01
CVE-2026-71366 Awx: notification backends allow ssrf and credential leakage CWE-918 7.7 High 2026-08-24
CVE-2026-71364 Awx: project archive extraction allows path traversal file writes CWE-22 7.2 High 2026-08-24
CVE-2026-71365 Awx: webhook status callback ssrf leaks the git pat CWE-918 7.7 High 2026-08-18
CVE-2026-12383 Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn CWE-345 7.5 High 2026-07-27
CVE-2026-12701 Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport CWE-22 9.0 Critical 2026-07-20
CVE-2026-12382 Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing CWE-290 8.2 High 2026-07-15
CVE-2026-11807 Eda-server: websocket missing authorization allows credential theft via activation_id spoofing CWE-862 9.6 Critical 2026-06-23
CVE-2026-52902 Awxkit: path traversal via yaml !include directive CWE-22 4.7 Medium 2026-06-09
CVE-2026-11332 Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution CWE-88 7.8 High 2026-06-05
CVE-2025-9909 Aap-gateway: improper path validation in gateway allows credential exfiltration CWE-647 6.7 Medium 2026-02-27
CVE-2025-9908 Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams CWE-200 6.7 Medium 2026-02-27

All 34 known CVE vulnerabilities affecting Red Hat Ansible Automation Platform 2.5 for RHEL 8 with full Chinese analysis, references, and POCs where available.