Red hat ansible automation platform 2
This hub aggregates every CVE we track for Red hat ansible automation platform 2, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
29
CVEs tracked
2
Critical
10
High
0
In CISA KEV
Severity distribution
MEDIUM14HIGH10LOW3CRITICAL2
Monthly trend
0
3
0
0
0
1
0
0
0
0
2
0
1
0
0
0
0
1
0
2
0
5
9
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat ansible automation platform 2.
- CVE-2026-18141Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header8.2
- CVE-2026-44191Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings7.8
- CVE-2026-44187Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api key3.3
- CVE-2026-44192Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltration via path traversal6.6
- CVE-2026-44190Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting7.8
- CVE-2026-44189Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filename7.8
- CVE-2026-16544Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure6.5
- CVE-2026-16493Ansible-core: argument injection in ansible-galaxy collection install via git clone (incomplete fix for cve-2026-11332)7.8
- CVE-2026-12701Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport9.0
- CVE-2026-12726Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential6.3
- CVE-2026-12398Galaxy_ng: shell injection in legacy role import via unsanitized git ref names7.5
- CVE-2026-44188Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration5.3
- CVE-2026-52902Awxkit: path traversal via yaml !include directive4.7
- CVE-2026-11332Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution7.8
- CVE-2026-6494Aap-mcp-server: aap mcp server: log injection allows social engineering attacks via unsanitized input5.3
Product normalization is registry-driven with AI assist and human review. How it works