CVE-2026-84486
- EPSS 0.52%
- Veröffentlicht 23.09.2026 18:35:50
- Zuletzt bearbeitet 24.09.2026 06:17:02
A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task, dependency, and workflow schedulers are configured to allow any user (including unauthenticated clients) and are routed...
CVE-2026-71462
- EPSS 0.26%
- Veröffentlicht 23.09.2026 18:25:22
- Zuletzt bearbeitet 24.09.2026 07:16:32
StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of arbitrary absolute paths on the controller-web pod. Tenant ...
CVE-2026-76648
- EPSS 0.24%
- Veröffentlicht 23.09.2026 18:24:44
- Zuletzt bearbeitet 26.09.2026 23:16:35
CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — ...
CVE-2026-92091
- EPSS 0.5%
- Veröffentlicht 16.09.2026 07:34:08
- Zuletzt bearbeitet 16.09.2026 19:42:43
A flaw was found in jwcrypto. The JWK.import_key() function validates the key_ops JWK member for duplicate values using an algorithm with O(n^2) time complexity, and the length of key_ops is not bounded. A remote, unauthenticated attacker can supply ...
CVE-2026-84470
- EPSS 0.24%
- Veröffentlicht 01.09.2026 20:57:09
- Zuletzt bearbeitet 24.09.2026 07:16:33
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job l...
CVE-2026-84232
- EPSS 0.18%
- Veröffentlicht 01.09.2026 15:18:59
- Zuletzt bearbeitet 01.09.2026 21:03:04
A flaw was found in pulpcore's content serving application. Files uploaded to Pulp file-type repositories are served with their original content type (e.g., text/html for .html files, image/svg+xml for .svg files) and without a Content-Disposition: a...
CVE-2026-79717
- EPSS 0.22%
- Veröffentlicht 25.08.2026 15:16:45
- Zuletzt bearbeitet 28.08.2026 18:58:27
A server-side request forgery (SSRF) vulnerability was found in galaxy_ng, the Ansible Galaxy server plugin for Pulp. An authenticated user with namespace management permissions can set a namespace avatar URL to an arbitrary address, including intern...
CVE-2026-71366
- EPSS 0.33%
- Veröffentlicht 24.08.2026 15:42:44
- Zuletzt bearbeitet 28.08.2026 21:17:10
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validati...
CVE-2026-71365
- EPSS 0.35%
- Veröffentlicht 18.08.2026 15:51:10
- Zuletzt bearbeitet 25.08.2026 09:17:32
A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload ...
CVE-2026-12564
- EPSS 0.26%
- Veröffentlicht 18.08.2026 15:50:54
- Zuletzt bearbeitet 24.09.2026 06:16:58
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL...