Skip to main content
EPSS 0.6%top 55%

CVE-2026-71366: Server-Side Request Forgery (SSRF) in Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8

0
High
VulnerabilityCVE-2026-71366cvecve-2026-71366gcvecwe-918
Published: 08/24/2026 (08/24/2026, 15:42:44 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2.5 for RHEL 8

Description

CVE-2026-71366 is a server-side request forgery (SSRF) vulnerability affecting multiple notification backends in Red Hat Ansible Automation Platform 2.5 for RHEL 8. The affected backends (webhook, Mattermost, Rocket.Chat, and Grafana) do not validate notification template URLs against private, loopback, or reserved IP ranges, allowing an organization notification administrator to cause the AWX control node to send HTTP requests to internal or loopback addresses. The webhook backend also follows HTTP redirects and resends Basic Authentication credentials to redirected hosts without validation, risking credential exfiltration. The Grafana backend exposes its API key to the configured target URL. Red Hat has rated this vulnerability as having an Important impact and has released a security update to fix it.

CVSS v3.1

Score 7.7high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Affected software

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 8

Red Hat

Red Hat Ansible Automation Platform 2.5 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.6 for RHEL 9

Red Hat

Red Hat Ansible Automation Platform 2.6

Red Hat

Red Hat Ansible Automation Platform 2.7

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 10:22:53 UTC

Technical Analysis

This SSRF vulnerability in Red Hat Ansible Automation Platform 2.5 for RHEL 8 affects multiple AWX notification backends by allowing notification template URLs to be used as direct HTTP request targets without validating against private or loopback IP ranges. An attacker with notification administrator privileges can create templates that cause the AWX control node to issue HTTP requests to internal services not externally accessible. The webhook backend exacerbates the risk by following HTTP redirects and resending Basic Authentication credentials to redirected hosts regardless of host changes, enabling credential exfiltration. The Grafana backend sends its API key in the Authorization header to the configured URL, exposing sensitive credentials. Red Hat advises restricting notification template creation to trusted administrators and applying network egress filtering until the update is applied. A security update fixing this vulnerability is available.

Potential Impact

An attacker with notification administrator privileges can exploit this SSRF vulnerability to make the AWX control node send HTTP requests to internal or loopback network services that are otherwise inaccessible externally. This can be used to probe internal infrastructure or exfiltrate sensitive credentials. The webhook backend's behavior of following redirects and resending Basic Authentication credentials can lead to credential leakage to attacker-controlled hosts. The Grafana backend exposes its API key to the configured target URL, risking unauthorized access. The vulnerability has a CVSS 3.1 score of 7.7 (high severity) with a high confidentiality impact but no integrity or availability impact.

Mitigation Recommendations

Red Hat has released an official security update that fixes this vulnerability and applying this update is the recommended remediation. Until the update is applied, customers should restrict the ability to create and modify notification templates to trusted administrators only. Network egress filtering should be implemented on Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local (169.254.0.0/16) IP ranges. Notification template configurations should be monitored for URLs pointing to internal or unusual addresses. Sensitive credentials such as Basic Authentication and Grafana API keys should not be configured in notification templates until the fix is applied. Existing notification templates should be audited for URLs pointing to internal services.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-08-06T04:27:34.372Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-71366","vendor":"Red Hat"}]

Threat ID: 6a8c68d6acd9273b49c4d34b

Added to database: 08/24/2026, 15:52:54 UTC

Last enriched: 09/10/2026, 10:22:53 UTC

Last updated: 10/07/2026, 06:48:18 UTC

Views: 72

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses