Skip to main content

CVE-2026-94416: Authentication Bypass by Spoofing in Red Hat Red Hat Ansible Automation Platform 2

0
Medium
VulnerabilityCVE-2026-94416cvecve-2026-94416
Published: 09/24/2026 (09/24/2026, 12:25:11 UTC)
Source: CVE Database V5
Vendor/Project: Red Hat
Product: Red Hat Ansible Automation Platform 2

Description

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will accept the forged WIT and return the AAP credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary.

CVSS v3.1

Score 6.8medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Affected software

Red Hat

Red Hat Ansible Automation Platform 2

Red Hat

Red Hat Ansible Automation Platform 2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/24/2026, 13:02:57 UTC

Technical Analysis

An authorization bypass vulnerability exists in the Ansible Automation Platform (AAP) gateway API that permits an authenticated administrator to create new service keys for the Controller service cluster outside the installer-provisioned path. These administrator-issued keys are cryptographically indistinguishable from legitimate keys and can be used to forge service-authentication tokens impersonating the Controller service. When combined with the gateway's OIDC workload-identity endpoint (enabled via FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED), attackers can coerce the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. Downstream resource servers trusting the gateway OIDC key, such as HashiCorp Vault, will accept these forged WITs and disclose AAP credentials bound to those workloads, thereby breaching the attacker's authorization boundary. The vulnerability leads to read-only disclosure of credentials used by AAP to automate managed infrastructure. Service keys created by administrators persist across upgrades, so auditing and revocation of non-installer-provisioned keys is critical. Disabling the workload-identity endpoint and rotating downstream credentials are recommended mitigations.

Potential Impact

The vulnerability allows an attacker with administrator privileges to bypass authorization controls and forge authentication tokens that impersonate the Controller service. This leads to unauthorized disclosure of AAP credentials from downstream resource servers such as HashiCorp Vault. The exposed credentials may include sensitive automation keys like cloud IAM keys, SSH private keys, or service-account credentials. The impact scope is changed because it extends beyond the gateway to trusted downstream services. The real-world business impact depends on the deployment and the nature of the credentials exposed. The vulnerability does not affect integrity or availability but results in high confidentiality impact.

Mitigation Recommendations

Red Hat advises auditing and revoking any Controller service keys not provisioned by the installer, especially for environments upgraded from AAP 2.5 or 2.6. If the workload-identity integration is not required, set FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED=false to disable the workload-identity endpoint. Additionally, rotate any downstream credentials (e.g., in HashiCorp Vault) that could have been accessed via forged workload identity tokens. These steps are the primary mitigations and should be prioritized. No official patch or fix version is explicitly stated in the advisory; check the vendor advisory for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2026-09-21T15:15:54.901Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-94416","vendor":"Red Hat"}]

Threat ID: 6ab51c22f7a7c5410652f61c

Added to database: 09/24/2026, 12:48:34 UTC

Last enriched: 09/24/2026, 13:02:57 UTC

Last updated: 09/25/2026, 01:56:00 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses