Skip to main content
EPSS 0.4%top 64%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update

0
Critical
Published: 01/08/2026 (01/08/2026, 19:41:55 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language.

Affected software

Affected versions
>=2.5.0 <2.6.0>=2.6.0Red HatRed Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6amd64registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:1466773e6bdf966c66e5cb101c436d8e75a183cc2ddd4c80acca1e7d59398cb7_amd64Red Hat Ansible Automation Platform 2.5registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:73bdb0e1a50031ea0e27d43ebb0149c705c4903b032f21fd66cf28b9dcca8543_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/17/2026, 18:05:03 UTC

Technical Analysis

CVE-2025-14025 is a security flaw in Red Hat Ansible Automation Platform (AAP) where read-only scoped OAuth2 API tokens, enforced at the gateway level, can perform write operations on backend services such as Controller, Hub, and EDA. This bypass occurs because the gateway does not properly restrict write operations for tokens intended to be read-only. The exploitability is limited by the permissions assigned to the user account associated with the token, making the impact dependent on the organization's RBAC policies. Attackers with tokens linked to users with elevated permissions could create or update execution environments, projects, or run job templates. Red Hat classifies this vulnerability as Important rather than Critical, emphasizing the need for careful token and permission management. No official fix has been released yet, but defense-in-depth strategies are recommended.

Potential Impact

If exploited, attackers with valid read-only tokens can perform unauthorized write operations on backend services, potentially modifying automation environments, projects, or job templates. The severity of impact depends on the permissions associated with the compromised token. Organizations that assign read-only tokens to individual users rather than restricted service accounts face higher risk. The vulnerability could lead to unauthorized changes in automation workflows, affecting confidentiality, integrity, and availability of automation processes.

Mitigation Recommendations

Red Hat advises using role-based access control (RBAC) to enforce the principle of least privilege and careful management of OAuth2 tokens to reduce risk. Organizations should avoid assigning read-only tokens to individual users and instead use dedicated service accounts with restricted permissions. Defense-in-depth practices are essential. No official patch or fix is currently available; users should monitor Red Hat advisories for updates and apply all previously released errata relevant to their systems. Refer to Red Hat article https://access.redhat.com/articles/7136004 for additional mitigation strategies.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:0408
Cve Count
2
Additional Cves
["CVE-2025-68664"]

Threat ID: 6a160988e29bf47b50652ede

Added to database: 05/26/2026, 20:58:48 UTC

Last enriched: 08/17/2026, 18:05:03 UTC

Last updated: 09/10/2026, 19:36:49 UTC

Views: 376

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses