CVE-2026-6266
- EPSS 0.04%
- Veröffentlicht 04.05.2026 14:16:35
- Zuletzt bearbeitet 04.05.2026 22:16:19
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This ...
CVE-2025-57847
- EPSS 0%
- Veröffentlicht 08.04.2026 13:55:00
- Zuletzt bearbeitet 01.05.2026 20:19:48
A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who ...
CVE-2025-9909
- EPSS 0.01%
- Veröffentlicht 27.02.2026 07:30:00
- Zuletzt bearbeitet 25.03.2026 20:18:06
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or social...
CVE-2025-9908
- EPSS 0%
- Veröffentlicht 27.02.2026 07:29:32
- Zuletzt bearbeitet 25.03.2026 20:19:13
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*)...
CVE-2025-9907
- EPSS 0.01%
- Veröffentlicht 27.02.2026 07:29:06
- Zuletzt bearbeitet 26.03.2026 16:56:31
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event ...
CVE-2025-14025
- EPSS 0.02%
- Veröffentlicht 08.01.2026 13:44:04
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on ba...
CVE-2025-5988
- EPSS 0.03%
- Veröffentlicht 04.08.2025 15:16:43
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in the Ansible aap-gateway. Cross-site request forgery (CSRF) origin checking is not done on requests from the gateway to external components, such as the controller, hub, and eda.
CVE-2025-7738
- EPSS 0.04%
- Veröffentlicht 31.07.2025 14:12:02
- Zuletzt bearbeitet 15.04.2026 00:35:42
A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub Enterprise authenticators in clear text. This vulnerability affects administrators or auditors accessing authenticator configurat...
CVE-2025-53861
- EPSS 0.04%
- Veröffentlicht 11.07.2025 12:44:17
- Zuletzt bearbeitet 11.08.2025 19:21:12
A flaw was found in Ansible. Sensitive cookies without security flags over non-encrypted channels can lead to Man-in-the-Middle (MitM) and Cross-site scripting (XSS) attacks allowing attackers to read transmitted data.
CVE-2025-53862
- EPSS 0.08%
- Veröffentlicht 11.07.2025 12:34:24
- Zuletzt bearbeitet 11.08.2025 19:20:55
A flaw was found in Ansible. Three API endpoints are accessible and return verbose, unauthenticated responses. This flaw allows a malicious user to access data that may contain important information.