Skip to main content
EPSS 0.3%top 74%

CVE-2026-12564: Server-Side Request Forgery (SSRF) in Red Hat Red Hat Ansible Automation Platform 2.4 for RHEL 8

0
Critical
VulnerabilityCVE-2026-12564cvecve-2026-12564gcvecwe-918
Published: 08/18/2026 (08/18/2026, 15:50:54 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2.4 for RHEL 8

Description

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.

CVSS v3.1

Score 9.6critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

Affected software

Red Hat

Red Hat Ansible Automation Platform 2.4 for RHEL 8

Red Hat

Red Hat Ansible Automation Platform 2.4 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 8

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.6 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.6

Red Hat

Red Hat Ansible Automation Platform 2.7

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/29/2026, 03:58:39 UTC

Technical Analysis

The vulnerability exists in the kubernetes_auth() function of the awx_plugins/credentials/hashivault.py file within the AAP Controller's HashiCorp Vault credential plugin. When a HashiCorp Vault Secret Lookup credential configured with kubernetes_role authentication is tested, the function reads the Kubernetes service account token of the controller pod and sends it to an attacker-controlled URL. An attacker with credential-creation privileges can exploit this to exfiltrate the token, thereby gaining unauthorized Kubernetes API access with extensive permissions, including the ability to create, read, update, and delete pods and secrets in control plane namespaces. This includes access to sensitive secrets such as database credentials and the Django SECRET_KEY. The vulnerability is present in all versions of AAP shipping the hashivault plugin with kubernetes_role support, affecting both on-premise and cloud deployments, with higher impact in cloud environments due to tenant isolation concerns.

Potential Impact

An authenticated attacker with credential-creation privileges can exfiltrate the Kubernetes service account token from the controller pod. This token grants the attacker Kubernetes API access to control plane namespaces with full pod CRUD and secret read permissions. Sensitive information such as database credentials and the Django SECRET_KEY can be accessed, potentially compromising the confidentiality and integrity of the environment. The vulnerability is critical due to the high privileges gained and the potential for widespread impact in managed cloud environments where tenant isolation is a key security boundary.

Mitigation Recommendations

Red Hat has not explicitly stated that a fix is available yet. Until a fix is released, mitigation involves restricting network egress from controller pods using Kubernetes NetworkPolicy to prevent outbound connections to untrusted destinations, allowing only known Vault server endpoints. Review and restrict RBAC permissions of the automation-controller service account to enforce least privilege and remove unnecessary secret read access. In cloud environments, audit credential-creation activities for suspicious Vault credentials with external or unusual URLs. Monitor Kubernetes audit logs for unexpected API calls by the automation-controller service account, especially secret reads and pod operations. Rotate the automation-controller service account token if unauthorized access is suspected. Consider limiting the 'create credential' privilege to trusted administrators until a fix is available. Check the Red Hat advisory for updates on patch availability.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-06-17T20:56:28.490Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-12564","vendor":"Red Hat"}]

Threat ID: 6a8482f3c6e8be03326f9af2

Added to database: 08/18/2026, 16:06:11 UTC

Last enriched: 09/29/2026, 03:58:39 UTC

Last updated: 10/02/2026, 02:46:02 UTC

Views: 87

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses