Red hat ansible automation platform 2.5 for rhel 8
This hub aggregates every CVE we track for Red hat ansible automation platform 2.5 for rhel 8, a product in the devtools ci space. Use it to gauge the current risk picture and drill into individual advisories.
49
CVEs tracked
7
Critical
16
High
0
In CISA KEV
Severity distribution
MEDIUM23HIGH16CRITICAL7LOW3
Monthly trend
1
3
0
0
0
2
0
0
2
1
1
0
0
0
0
1
3
0
0
1
3
3
4
23
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat ansible automation platform 2.5 for rhel 8.
- CVE-2026-84724Automation-controller: automation-controller: systemjob extra_vars.days argument injection into uncontainerized control-plane awx-manage process6.6
- CVE-2026-84720Automation-controller: automation-controller: workflowjobnode.ancestor_artifacts lacks prevent_search, exposing no_log set_stats artifacts via orm-traversal count-oracle6.5
- CVE-2026-84718Automation-controller: automation-controller: client ip spoofing in audit/access logs via unrestricted x-forwarded-for trust4.3
- CVE-2026-84717Automation-controller: automation-controller: unauthenticated 200-vs-403 oracle in bitbucket data center webhook receiver enumerates webhook-enabled job templates5.3
- CVE-2026-84716Automation-controller: automation-controller: instance install_bundle issues 10-year, non-revocable receptor mesh-ca certificates for caller-chosen (and case-variant impersonating) hostnames6.6
- CVE-2026-84712Automation-controller: automation-controller: unauthenticated /api/v2/ping/ discloses automation-mesh instance topology and instance-group membership5.3
- CVE-2026-84719Automation-controller: automation-controller: workflowjobtemplate /copy/ deep-copy sanitizer omits instance_groups authorization (instancegroup use_role bypass to control-plane)9.9
- CVE-2026-84714Automation-controller: automation-controller: incomplete sanitize_jinja() regex allows jinja template injection into ad-hoc module_args, machine-credential fields, and host names, reaching ansible-core templating in the execution environment7.1
- CVE-2026-84706Automation-controller: automation-controller-container: automation-controller: credential type env-injector deny-list omits process-hijacking variables (bash_env/ld_preload) allowing code execution in the execution environment7.6
- CVE-2026-75884Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups9.1
- CVE-2026-84691Automation-controller: automation-controller-container: automation-controller: format string injection in the api 4xx error log setting discloses django secret_key and database credentials to an administrator8.7
- CVE-2026-84683Automation-controller: automation-controller-container: automation-controller: stored cross-site scripting in the job stdout html view via ansi osc 8 hyperlink sequences (javascript: anchor) enabling session takeover8.7
- CVE-2026-84499Automation-controller: automation-controller-container: automation-controller: write-only survey password recovered in plaintext via schedule/workflowjobtemplatenode survey min/max validation error message7.7
- CVE-2026-84502Automation-controller: automation-controller-container: automation-controller: project scm_url argument injection into `git ls-remote --upload-pack` yields rce on the controller-task control-plane pod9.9
- CVE-2026-84474Automation-controller: automation-controller-container: automation-controller: view_jobtemplate to execute privilege escalation via host_config_key exposure and x-forwarded-for spoofing of provisioning-callback host match9.9
Product normalization is registry-driven with AI assist and human review. How it works