CVE-2026-71365
- EPSS 0.35%
- Veröffentlicht 18.08.2026 15:51:10
- Zuletzt bearbeitet 20.08.2026 13:08:53
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload ...
CVE-2026-12564
- EPSS 0.26%
- Veröffentlicht 18.08.2026 15:50:54
- Zuletzt bearbeitet 20.08.2026 13:08:53
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL...
CVE-2026-19730
- EPSS 0.11%
- Veröffentlicht 13.08.2026 18:17:25
- Zuletzt bearbeitet 14.08.2026 19:07:46
The 'podman quadlet install --replace' command opens the existing destination file with O_CREATE|O_WRONLY but omits O_TRUNC. When the initial reflink copy attempt fails (common on non-reflink-capable filesystems including many RHEL default XFS config...
CVE-2026-12383
- EPSS 0.16%
- Veröffentlicht 27.07.2026 19:17:14
- Zuletzt bearbeitet 04.08.2026 21:16:34
A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowAny], authentication_classes=[]) and relies solely on the Subject HTTP header value for mTLS authentic...
CVE-2026-44191
- EPSS 0.82%
- Veröffentlicht 22.07.2026 12:11:29
- Zuletzt bearbeitet 22.07.2026 19:17:03
A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling of the ansible.executionEnvironment.containerOptions and ansible.executionEnvironment.volumeMounts se...
CVE-2026-44189
- EPSS 0.95%
- Veröffentlicht 22.07.2026 12:06:36
- Zuletzt bearbeitet 22.07.2026 16:23:35
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the...
CVE-2026-16544
- EPSS 0.39%
- Veröffentlicht 22.07.2026 11:15:53
- Zuletzt bearbeitet 22.07.2026 18:16:59
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_upda...
CVE-2026-11807
- EPSS 0.42%
- Veröffentlicht 23.06.2026 19:40:33
- Zuletzt bearbeitet 16.07.2026 12:17:00
A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged mess...
CVE-2026-12398
- EPSS 0.89%
- Veröffentlicht 16.06.2026 14:52:06
- Zuletzt bearbeitet 29.06.2026 18:16:36
A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (v1) interpolates unsanitized git ref names (branch/tag names) into shell commands executed via subprocess.run() with shell=True. A...
CVE-2026-44188
- EPSS 0.28%
- Veröffentlicht 15.06.2026 08:36:06
- Zuletzt bearbeitet 20.08.2026 16:17:23
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authoriz...