Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-12564: Server-Side Request Forgery (SSRF) in Red Hat Red Hat Ansible Automation Platform 2

0
Critical
VulnerabilityCVE-2026-12564cvecve-2026-12564
Published: 08/18/2026 (08/18/2026, 15:50:54 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2

Description

CVE-2026-12564 is a critical Server-Side Request Forgery (SSRF) vulnerability in the HashiCorp Vault credential plugin of Red Hat Ansible Automation Platform 2. The vulnerability allows an authenticated attacker with credential-creation privileges to exfiltrate the Kubernetes service account token from the controller pod. This token grants Kubernetes API access with full pod CRUD and secret read permissions, including sensitive credentials such as database passwords and the Django SECRET_KEY. The flaw affects all AAP Controller deployments using the hashivault credential plugin with kubernetes_role authentication. Mitigations include restricting network egress from controller pods, limiting RBAC permissions, auditing credential creation, monitoring Kubernetes audit logs, rotating tokens if compromise is suspected, and restricting credential creation privileges until a fix is available.

CVSS v3.1

Score 9.6critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/18/2026, 16:20:01 UTC

Technical Analysis

A flaw in the AAP Controller's HashiCorp Vault credential plugin (awx_plugins/credentials/hashivault.py) allows an authenticated attacker with credential-creation privileges to exploit the kubernetes_auth() function. This function reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when testing a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication. Exfiltration of this token enables the attacker to access the Kubernetes API for control plane namespaces with full pod create, read, update, delete (CRUD) and secret read permissions, exposing sensitive data including database credentials and the Django SECRET_KEY. The vulnerability impacts both on-premise and AAP Cloud deployments, with higher impact in managed cloud environments due to tenant isolation boundaries. The vulnerable code path exists in all AAP versions shipping the hashivault credential plugin with kubernetes_role support. No official fix or patch is currently confirmed. Red Hat recommends network egress restrictions, RBAC permission tightening, auditing, monitoring, token rotation, and limiting credential creation privileges as mitigations.

Potential Impact

An attacker with authenticated access and credential-creation privileges can exfiltrate the Kubernetes service account token from the controller pod. This token provides broad Kubernetes API access to control plane namespaces, allowing full pod management and secret reading capabilities. Sensitive information such as database credentials and the Django SECRET_KEY can be compromised. This can lead to significant confidentiality and integrity impacts within the Kubernetes environment managed by the Ansible Automation Platform. The vulnerability does not impact availability. The impact is more severe in cloud-managed environments where tenant isolation is critical.

Mitigation Recommendations

No official patch or fix is currently confirmed by Red Hat. Until a fix is available, Red Hat recommends the following mitigations: restrict network egress from controller pods using Kubernetes NetworkPolicy to prevent outbound connections to untrusted destinations and only allow connections to known Vault server endpoints; review and restrict RBAC permissions of the automation-controller service account to follow least privilege principles, removing unnecessary secret read access; audit credential-creation activity for suspicious HashiCorp Vault credentials with external or unusual URLs in AAP Cloud environments; monitor Kubernetes audit logs for unexpected API calls using the automation-controller service account, especially secret reads and pod operations; rotate the automation-controller service account token if unauthorized access is suspected; and consider restricting the 'create credential' privilege to trusted administrators only until a fix is released.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-06-17T20:56:28.490Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-12564","vendor":"Red Hat"}]

Threat ID: 6a8482f3c6e8be03326f9af2

Added to database: 08/18/2026, 16:06:11 UTC

Last enriched: 08/18/2026, 16:20:01 UTC

Last updated: 08/18/2026, 16:24:19 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses