Red hat ansible automation platform 2.6 for rhel 9
This hub aggregates every CVE we track for Red hat ansible automation platform 2.6 for rhel 9, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
2
Critical
9
High
0
In CISA KEV
Severity distribution
HIGH9MEDIUM4CRITICAL2
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
3
0
0
1
3
4
3
0
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Red hat ansible automation platform 2.6 for rhel 9.
- CVE-2026-71366Awx: notification backends allow ssrf and credential leakage7.7
- CVE-2026-71364Awx: project archive extraction allows path traversal file writes7.2
- CVE-2026-71365Awx: webhook status callback ssrf leaks the git pat7.7
- CVE-2026-18141Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header8.2
- CVE-2026-12383Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn7.5
- CVE-2026-12701Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport9.0
- CVE-2026-12382Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing8.2
- CVE-2026-11807Eda-server: websocket missing authorization allows credential theft via activation_id spoofing9.6
- CVE-2026-52902Awxkit: path traversal via yaml !include directive4.7
- CVE-2026-11332Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution7.8
- CVE-2026-6266Aap-controller: aap-gateway: account hijacking and unauthorized access via unverified email linking8.3
- CVE-2025-9909Aap-gateway: improper path validation in gateway allows credential exfiltration6.7
- CVE-2025-9908Event-driven-ansible: sensitive internal headers disclosure in aap eda event streams6.7
- CVE-2025-9907Event-driven-ansible: event stream test mode exposes sensitive headers in aap eda6.7
- CVE-2025-14025Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions8.5
Product normalization is registry-driven with AI assist and human review. How it works