Junglewise Threat Intelligence

CVE-2026-11807: Red Hat Ansible Automation Platform missing authorization in EDA websocket API

CVE-2026-11807 · Severity: critical · CVSS 9.6 · Published 2026-06-23

Technologies: Red Hat Ansible Automation Platform 2. Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA) component, which is used to automate IT tasks based on system events. An authenticated user can exploit this flaw to steal sensitive credentials, such as SSH keys, vault passwords, and OAuth tokens, belonging to other automation tasks. This could lead to unauthorized access to managed infrastructure and significant data exposure.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Event-Driven Ansible (EDA) websocket API at the /api/eda/ws/ansible-rulebook endpoint. The component fails to verify user permissions when processing Worker messages. An attacker with low-privileged authenticated access can send a forged message containing an arbitrary activation_id. This allows the attacker to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys. Red Hat has released security advisories (RHSA-2026:28492 and RHSA-2026:28497) to address this issue in Ansible Automation Platform 2.5 and 2.6.

Affected products

  • Red Hat Ansible Automation Platform 2.5 eda-controller-rhel8
  • Red Hat Ansible Automation Platform 2.6 eda-controller-rhel9
  • Red Hat Ansible Automation Platform 2 automation-eda-controller

Timeline

  • 2026-06-23: disclosed
  • 2026-06-23: advisory: Red Hat Security Advisory RHSA-2026:28492 and RHSA-2026:28497 published
  • 2026-06-23: patched

References