Junglewise Threat Intelligence

CVE-2026-94416: Red Hat Ansible Automation Platform authorization bypass in gateway

CVE-2026-94416 · Severity: medium · CVSS 6.8 · Published 2026-09-24

Technologies: Red Hat Ansible Automation Platform. Vendors: Red Hat.

Executive brief

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway that allows an authenticated administrator to forge service authentication tokens and request unauthorized Workload Identity Tokens. When the OIDC workload-identity feature is enabled, an attacker can leverage forged tokens to impersonate arbitrary Controller workloads and extract sensitive credentials from downstream systems such as HashiCorp Vault, including cloud keys, SSH private keys, and service-account credentials that far exceed their original authorization scope.

Technical details

An authenticated administrator can create a service key that is cryptographically indistinguishable from installer-provisioned keys due to lack of restriction on the service-key creation path. When FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED is active, the attacker can forge service-authentication tokens to drive the gateway's OIDC endpoint into signing Workload Identity Tokens for arbitrary Controller workloads, enabling token forgery attacks. A downstream OIDC-trusting resource server will accept the forged WIT and return credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary.

Affected products

  • Red Hat Ansible Automation Platform 2.5 through 2.7

Timeline

  • 2026-09-24: disclosed

References

Related threats