Skip to main content
EPSS 0.2%top 94%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update

0
High
Published: 10/28/2025 (10/28/2025, 21:16:15 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Update(s) and Fix(es): * Fixes issue that prevents SAML and AzureAD authentication when local user accounts share the same email address (AAP-56518) * Updated error handling in the Authenticator form to match other forms in the Platform UI. API errors for specific fields are correctly mapped to the form fields in the UI (AAP-56356) * Fixed issue with the lightspeed containers configuration when running installation for the second time over the existing AAP (AAP-56263) * Changes in the deployment and nginx configuration now allow for gunicorn and daphne to bind to :: as well, essentially allowing for seamlessly binding to IPv4 and IPv6 (dual-stack) addresses, while also enabling the operator to run in single-stack IPv6 or IPv4 scenarios (AAP-56192) * Update autocomplete settings (AAP-55783) * Fix an issue when restoring an upgraded AAP environment from 2.4 (AAP-55648) * Fixed a bug where the user could set an image without the respective version, causing the installation to enter an error loop (AAP-55642) * Fixed a bug that caused a failure to gather the job data from the controller API (AAP-55632) * Address the duplication issue by adding labels (AAP-55621) * Fixed Platform Auditor to view controller settings (AAP-55607) * Fixed an issue where setting automationgateway_disable_https=false resulted in install failure (AAP-55466) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55183) * Set REDHAT_CANDLEPIN_VERIFY to correct CA pem so that controller can make requests to subscription.rhsm.redhat.com (AAP-55180) * Added a step in the subscription wizard that allows the user to configure automation analytics (AAP-55094) * Added postgres_extra_settings to AAP operators to apply postgresql configuration file level changes to managed postgres (AAP-55053) * Subscription credentials can no longer be viewed/edited from the system settings page (AAP-55014) * Add support for Red Hat username and password for the subscription management API (AAP-54975) * Fixes system_administrator role creation race condition which most commonly happened on new openshift deployments resulting in the default instance group not being created (AAP-54963) * Fixed issue where RESOURCE_KEY SECRET_KEY was not updated when restoring from a different environment (AAP-54942) * Updated ansible-builder and ansible-navigator to use EE images from ansible-automation-platform-26 namespace by default (AAP-54934) * Fix the permission list when creating a custom role and selecting the Automation Decisions project or credential types (AAP-54756) * Settings display "Red Hat" consistently in the API and UI (AAP-54276) * Fix _ui/v2/ user detail displays data correctly (AAP-54260) * Fix Ansible Lightspeed API version during AAP idle (AAP-54174) * Fix error in lightspeed service when upgrading from AAP 2.5 to AAP 2.6 (AAP-54064) * Fix "Load More" in Authentication Mapping Role dropdown doesn't work (AAP-54049) * Replaced dropdown type for decision environments on the rulebook activation form so that when there are no decision environments available, dropdown displays "No results found" instead of an empty dropdown (AAP-53844) * This version of receptor addresses improves stability on long-running jobs, clusters under heavy load and network flakiness (AAP-53742) * Axios package version was updated (AAP-53718) * Component label for Platform Auditor role was fixed to display all components (AAP-53551) * Fixed an issue where automation gateway's envoy.log did not receive logs after it was rotated (AAP-51779) * Topology layout and full screen mode were fixed (AAP-51106) * Empty strings are no longer displayed in the extra variables field on the Jobs > Details page (AAP-49448) * Added two new toggle options on the subscription wizard to allow for fetching subscriptions using basic authentication (AAP-47865) * Controller Red Hat Ansible Automation Platform now works with ansible.platform collection (AAP-41000) * Fixed default execution environment selection in the automation settings page (AAP-39321)

Affected software

Affected versions
>=2.5.0 <2.6.0=2.6Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.5 for RHEL 9Red Hat Ansible Automation Platform 2.5amd64registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:fb284b670f3c4c28ac3bcc6a16d20db5ec38165750baf6a03f1d3b7cc316027f_amd64Red Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:dae29680daff4810413849c1458c08d1d2bb6a07074cbd4c1eccacd109b9374c_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 20:20:18 UTC

Technical Analysis

This advisory covers several security vulnerabilities in Red Hat Ansible Automation Platform 2.5, including CVE-2025-64459 (Django SQL injection), CVE-2025-9907 and CVE-2025-9908 (sensitive internal headers disclosure in AAP EDA event streams), and CVE-2025-9909 (improper path validation in automation-gateway allowing credential exfiltration). The vulnerabilities affect multiple components of the platform and could expose sensitive information or allow unauthorized access. Red Hat has issued updates that fix these vulnerabilities and other bugs. The advisory includes detailed package updates and instructions for applying the fixes. No known exploits in the wild have been reported at this time.

Potential Impact

The vulnerabilities could allow attackers to perform SQL injection attacks, disclose sensitive internal headers, and exfiltrate credentials due to improper path validation. This may lead to unauthorized access to sensitive data or disruption of automation workflows. The severity is rated as high by Red Hat Product Security. However, no active exploitation has been reported.

Mitigation Recommendations

Red Hat has released official patches for Red Hat Ansible Automation Platform 2.5 addressing these vulnerabilities. Users should apply the updates as detailed in the Red Hat advisories RHSA-2025:23069 and RHSA-2025:23131. The advisories provide updated package versions and instructions for upgrading. Applying these updates mitigates the vulnerabilities. No additional workarounds or mitigations are indicated by the vendor.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2025:23069
Cve Count
6
Additional Cves
["CVE-2025-9908","CVE-2025-9909","CVE-2025-58754","CVE-2025-59530","CVE-2025-64459"]

Threat ID: 6a1f4e87e29bf47b50080a1f

Added to database: 06/02/2026, 21:43:35 UTC

Last enriched: 08/13/2026, 20:20:18 UTC

Last updated: 09/10/2026, 19:36:52 UTC

Views: 139

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses