Red Hat Ansible Automation Platform
78 known vulnerabilities in Red Hat Ansible Automation Platform, 10 critical, 3 actively exploited, with patch priority, exploit likelihood and the news…
Recently exploited
- CVE-2026-48710 CVSS 6.5 medium · actively exploited Kludex Starlette HTTP Request/Response Smuggling Vulnerability
- CVE-2026-42271 CVSS 8.7 high · actively exploited BerriAI LiteLLM Command Injection Vulnerability
- CVE-2026-42208 CVSS 9.3 critical · actively exploited BerriAI LiteLLM SQL Injection Vulnerability
Latest vulnerabilities
- CVE-2026-103754 CVSS 5.9 medium A flaw was found in ansible-runner. The unstream_dir() function, which receives and extracts a streamed zip archive on the worker side of…
- CVE-2026-90959 CVSS 8.1 high A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows users with file…
- CVE-2026-94416 CVSS 6.8 medium An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator…
- CVE-2026-85475 CVSS 7.2 high A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration is generated by…
- CVE-2026-84724 CVSS 6.6 medium An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The system-job…
- CVE-2026-84721 CVSS 6.4 medium A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The…
- CVE-2026-84720 CVSS 6.5 medium A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts database column, which…
- CVE-2026-84719 CVSS 9.9 critical A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission…
- CVE-2026-84718 CVSS 4.3 medium A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the Controller trusts…
- CVE-2026-84717 CVSS 5.3 medium A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver…
- CVE-2026-84716 CVSS 6.6 medium A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administrator downloads an execution/hop…
- CVE-2026-84714 CVSS 7.1 high A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function uses two regular expressions to reject…
- CVE-2026-84713 CVSS 6.5 medium A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.notification_ configuration is…
- CVE-2026-84712 CVSS 5.3 medium A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/ping/ (ApiV2PingView, AllowAny)…
- CVE-2026-84706 CVSS 7.6 high A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector…
- CVE-2026-84691 CVSS 8.7 high A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log message emitted for API…
- CVE-2026-84683 CVSS 8.7 high A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update…
- CVE-2026-75884 CVSS 9.1 critical A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts…
- CVE-2026-84502 CVSS 9.9 critical A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against…
- CVE-2026-84499 CVSS 7.7 high A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and…
- CVE-2026-84486 CVSS 8.2 high A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Four debug views that trigger the internal task…
- CVE-2026-84474 CVSS 9.9 critical A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is…
- CVE-2026-76648 CVSS 8.5 high CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level…
- CVE-2026-71465 CVSS 3.1 low RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using args.extend(['-l', limit]) like…
- CVE-2026-71464 CVSS 3.1 low LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike Project/JobTemplate/JobLaunch…
- CVE-2026-71463 CVSS 2.7 low Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job'+'_env']) and {% if job.id >…
- CVE-2026-71462 CVSS 4.1 medium StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. 200 vs 400 response reveals existence of…
- CVE-2026-71461 CVSS 4.3 medium HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated user triggers Django FieldError…
- CVE-2026-71460 CVSS 4.3 medium /api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_id, sku, support_level, instance…
- CVE-2026-71459 CVSS 5.0 medium JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() falls through (returns True) for…