CVE-2026-71366: Server-Side Request Forgery (SSRF) in Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8
Description
CVE-2026-71366 is a server-side request forgery (SSRF) vulnerability affecting multiple notification backends in Red Hat Ansible Automation Platform 2.5 for RHEL 8. The affected backends (webhook, Mattermost, Rocket.Chat, and Grafana) do not validate notification template URLs against private, loopback, or reserved IP ranges, allowing an organization notification administrator to cause the AWX control node to send HTTP requests to internal or loopback addresses. The webhook backend also follows HTTP redirects and resends Basic Authentication credentials to redirected hosts without validation, risking credential exfiltration. The Grafana backend exposes its API key to the configured target URL. Red Hat has rated this vulnerability as having an Important impact and has released a security update to fix it.
CVSS v3.1
Score 7.7high
Affected software
Red Hat
Red Hat Ansible Automation Platform 2.5 for RHEL 8
Red Hat
Red Hat Ansible Automation Platform 2.5 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2.6
Red Hat
Red Hat Ansible Automation Platform 2.7
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This SSRF vulnerability in Red Hat Ansible Automation Platform 2.5 for RHEL 8 affects multiple AWX notification backends by allowing notification template URLs to be used as direct HTTP request targets without validating against private or loopback IP ranges. An attacker with notification administrator privileges can create templates that cause the AWX control node to issue HTTP requests to internal services not externally accessible. The webhook backend exacerbates the risk by following HTTP redirects and resending Basic Authentication credentials to redirected hosts regardless of host changes, enabling credential exfiltration. The Grafana backend sends its API key in the Authorization header to the configured URL, exposing sensitive credentials. Red Hat advises restricting notification template creation to trusted administrators and applying network egress filtering until the update is applied. A security update fixing this vulnerability is available.
Potential Impact
An attacker with notification administrator privileges can exploit this SSRF vulnerability to make the AWX control node send HTTP requests to internal or loopback network services that are otherwise inaccessible externally. This can be used to probe internal infrastructure or exfiltrate sensitive credentials. The webhook backend's behavior of following redirects and resending Basic Authentication credentials can lead to credential leakage to attacker-controlled hosts. The Grafana backend exposes its API key to the configured target URL, risking unauthorized access. The vulnerability has a CVSS 3.1 score of 7.7 (high severity) with a high confidentiality impact but no integrity or availability impact.
Mitigation Recommendations
Red Hat has released an official security update that fixes this vulnerability and applying this update is the recommended remediation. Until the update is applied, customers should restrict the ability to create and modify notification templates to trusted administrators only. Network egress filtering should be implemented on Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local (169.254.0.0/16) IP ranges. Notification template configurations should be monitored for URLs pointing to internal or unusual addresses. Sensitive credentials such as Basic Authentication and Grafana API keys should not be configured in notification templates until the fix is applied. Existing notification templates should be audited for URLs pointing to internal services.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-08-06T04:27:34.372Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-71366","vendor":"Red Hat"}]
Threat ID: 6a8c68d6acd9273b49c4d34b
Added to database: 08/24/2026, 15:52:54 UTC
Last enriched: 09/10/2026, 10:22:53 UTC
Last updated: 10/07/2026, 06:48:18 UTC
Views: 72
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.