Executive brief
A security flaw in the Red Hat Ansible Automation Platform (AAP) gateway allows unauthorized users to take over existing accounts. The system's 'auto-link' feature incorrectly connects external login identities to internal accounts based only on an email address without verifying that the user actually owns that email. This could allow an attacker to hijack administrative accounts, potentially gaining full control over the organization's automation infrastructure and sensitive data.
Technical details
A vulnerability exists in the user auto-link strategy of the Red Hat Ansible Automation Platform (AAP) gateway, specifically within the automation-gateway and automation-controller components. The root cause is an authentication bypass (CWE-305) where the system automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. A remote attacker with low privileges (the ability to provide a specific email via an IDP) can hijack victim accounts, including those with administrative privileges. This issue affects AAP versions 2.5 and 2.6. Red Hat has released security advisories (RHSA-2026:13508, RHSA-2026:13512) providing patches for affected versions.
Affected products
- Red Hat Ansible Automation Platform 2.5 2.5
- Red Hat Ansible Automation Platform 2.6 2.6
- Red Hat Ansible Automation Platform Gateway
- Red Hat Ansible Automation Platform Controller
Timeline
- 2026-05-04: disclosed
- 2026-05-04: advisory: Red Hat issued RHSA-2026:13508 and RHSA-2026:13512
- 2026-05-04: patched
References
- https://access.redhat.com/downloads/content/package-browser/
- https://catalog.redhat.com/software/containers/
- https://access.redhat.com/errata/RHSA-2026:13508
- https://access.redhat.com/errata/RHSA-2026:13512
- https://access.redhat.com/errata/RHSA-2026:13545
- https://access.redhat.com/security/cve/CVE-2026-6266
- https://bugzilla.redhat.com/show_bug.cgi?id=2458142