All 5 CVE vulnerabilities found in Red Hat Ansible Automation Platform 2, with AI-generated Chinese analysis, references, and POCs.
Vendor: Red Hat
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-6494 | Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input CWE-117 | 5.3 | Medium | 2026-04-17 |
| CVE-2025-57847 | Ansible-automation-platform: privilege escalation via excessive group writable /etc/passwd permissions CWE-276 | 6.4 | Medium | 2026-04-08 |
| CVE-2026-0598 | Ansible-lightspeed: broken object level authorization leading to cross-user ai conversation context injection in ansible lightspeed api CWE-283 | 4.2 | Medium | 2026-02-06 |
| CVE-2025-53861 | Aap: sensitive cookie(s) set without security flags CWE-319 | 3.1 | Low | 2025-07-11 |
| CVE-2025-53862 | Aap: aap-gateway: automation-hub: sensitive information disclosure CWE-497 | 3.5 | Low | 2025-07-11 |
All 5 known CVE vulnerabilities affecting Red Hat Ansible Automation Platform 2 with full Chinese analysis, references, and POCs where available.