CVE-2026-71364: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Description
CVE-2026-71364 is a path traversal vulnerability in the project_archive action plugin of AWX, part of Red Hat Ansible Automation Platform 2.5 for RHEL 8. The plugin extracts archive members without proper path normalization or boundary validation, allowing malicious archives to write files outside the intended directory. This can lead to arbitrary file writes as the user performing the extraction, potentially enabling remote code execution. The vulnerability affects both containerized and RPM-based deployments, with higher impact on the latter due to host-level extraction. Red Hat has released an update addressing this issue.
CVSS v3.1
Score 7.2high
Affected software
Red Hat
Red Hat Ansible Automation Platform 2.5 for RHEL 8
Red Hat
Red Hat Ansible Automation Platform 2.5 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2.6
Red Hat
Red Hat Ansible Automation Platform 2.7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because the project_archive action plugin in AWX joins archive member filenames to the project directory path without validating or normalizing the paths, permitting directory traversal sequences. An attacker controlling the archive content can write files anywhere on the execution node filesystem with the privileges of the extraction user. This can lead to remote code execution via mechanisms such as cron jobs, SSH authorized keys, or playbook injection. The issue is known as a Zip Slip vulnerability. In containerized deployments, the impact may be limited by container isolation, whereas in RPM-based deployments the extraction runs on the host with AWX service user privileges, increasing risk. Red Hat Ansible Automation Platform 2.5 ships the affected code as part of Automation Controller. Red Hat has assessed the impact as Important and has released a security update to fix the vulnerability.
Potential Impact
Successful exploitation allows an attacker who can supply or manipulate archive content to write arbitrary files on the execution node with the privileges of the AWX service user. This can lead to remote code execution, confidentiality breaches, integrity violations, and denial of service by overwriting critical files. The vulnerability affects both containerized and RPM-based deployments, with potentially greater impact on RPM-based due to host-level extraction privileges. The CVSS v3.1 base score is 7.2 (High), reflecting network attack vector, low complexity, high privileges required, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released an official security update that fixes this vulnerability; applying this update is the recommended remediation. Until the fix is applied, customers should avoid using archive-type projects (scm_type='archive') and prefer Git-based projects instead. Additionally, ensure all archive source URLs use HTTPS with valid certificates to prevent man-in-the-middle attacks, and only use archive sources from trusted providers. Restrict project creation and modification permissions to trusted administrators. In containerized deployments, minimize host volume mounts and run extraction with minimal filesystem permissions to reduce exposure.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-06T04:27:34.372Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-71364","vendor":"Red Hat"}]
Threat ID: 6a8c6554acd9273b49bc99ba
Added to database: 08/24/2026, 15:37:56 UTC
Last enriched: 09/10/2026, 10:37:21 UTC
Last updated: 10/08/2026, 18:48:48 UTC
Views: 69
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.