Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 76%

Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update

0
High
Published: 08/04/2026 (08/04/2026, 21:39:16 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section.

Affected software

Affected versions
=24.0>=2.6.0 <2.7.0Red HatRed Hat OpenShift AIRed Hat OpenShift AI 3.2arm64registry.redhat.io/rhai/base-image-cpu-rhel9@sha256:a057aa96b1ec4b49cc4958c7e503f842e9f0be1b3de0be45bb65abdeba336ae7_arm64Red Hat OpenShift AI 3.3amd64registry.redhat.io/rhai/base-image-neuron-rhel9@sha256:78962943076c2110c14ea51d5182d6de783345d8075821c02226e5c0e3f89864_amd64ppc64leregistry.redhat.io/rhai/base-image-spyre-rhel9@sha256:7fcdc832b324da46b8f84e5c2cce16d7bf2e1dbdb1f66f9a1155e8f38f845488_ppc64leRed Hat Enterprise LinuxRed Hat Enterprise Linux AppStream (v. 9)noarchpython3.14-pip-0:25.2-3.el9_8.5.noarchRed Hat Hardened Imagessrcpython-pip-main@src24.0registry.redhat.io/rhai/base-image-cuda-12.9-rhel9@sha256:4287fddfa6a3ed6a6ae0db82eafdd4b5132366961ec1de7bab7483a23926454e_arm64Red Hat Ansible Automation PlatformRed Hat Ansible Automation Platform 2.6registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:62c5e15e425dd562e0a8199e437cdbd2f29e239bd758c25c893ef0a60e767128_amd64registry.redhat.io/rhai/base-image-rocm-6.4-rhel9@sha256:a498ed6935e49517ca753a9dbbda7b596253c5a63929686bd62a5062859acb9d_amd64registry.redhat.io/rhai/base-image-rocm-7.0-rhel9@sha256:acf5a461dbe77edb3f3cc0f0fe87211b652a57371d5a8d9f8272b827bf6cbd67_amd64registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:86f8a6c4738e39340446579315f85e3c7384f7e65cbded41f23d6ff7d9e7b6b6_amd64Red Hat OpenShift AI 3.0registry.redhat.io/rhai/base-image-spyre-rhel9@sha256:0ab370e131bb12b7e37a13feae2b7c7c2def72bc0453ea327983226d855d9d3b_amd64registry.redhat.io/rhai/base-image-cpu-rhel9@sha256:6aa195a0182fd0129fd849631362890b7c96dc1a234a2f54730b7d254b4903e0_arm64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 22:57:21 UTC

Technical Analysis

CVE-2026-12701 is a path traversal vulnerability in the pulpcore component of Red Hat Ansible Automation Platform 2.6. The relative_path_validator function fails to block directory traversal sequences such as "../" within content paths, allowing an authenticated administrator to craft paths that escape the intended export directory during FilesystemExport operations. Because the file content is user-controlled, this enables arbitrary file writes to any location writable by the pulp service user, potentially leading to service compromise or further exploitation. The FilesystemExport API is restricted to admin-level users, and the pulp process runs as a non-root user with write access to service-critical paths. Attack vectors include overwriting cron.d entries or Pulp configuration files. Red Hat Satellite and Ansible Automation Hub ship pulpcore and are affected. The vendor advisory provides detailed mitigation steps and a security update.

Potential Impact

An authenticated administrator can write arbitrary files outside the intended export directory, potentially overwriting critical system or service files writable by the pulp user. This can lead to service compromise, unauthorized code execution, confidentiality breaches by reading sensitive files, and denial of service through corruption or deletion of important data. The vulnerability impacts integrity, confidentiality, and availability of the affected system. However, exploitation requires admin-level privileges and authentication.

Mitigation Recommendations

A security update is available from Red Hat for Ansible Automation Platform 2.6 and should be applied. Before updating, ensure all previously released errata are applied. If FilesystemExport was never configured, the system is not affected. Existing FilesystemExporters should be audited for path traversal sequences and cleaned manually if found. Restrict admin-level access to trusted operators only. Ensure SELinux is in enforcing mode to limit pulp user's write access. Monitor filesystem changes outside expected directories for signs of exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:34891
Cve Count
1
Additional Cves
[]
Cvss Version
null

Threat ID: 6a46ece427e9c79719440eb9

Added to database: 07/02/2026, 22:57:40 UTC

Last enriched: 08/14/2026, 22:57:21 UTC

Last updated: 09/01/2026, 22:52:14 UTC

Views: 195

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:42132https://access.redhat.com/security/cve/CVE-2026-12701https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39373https://access.redhat.com/security/cve/CVE-2026-39821https://access.redhat.com/security/cve/CVE-2026-42561https://access.redhat.com/security/cve/CVE-2026-44431https://access.redhat.com/security/cve/CVE-2026-44432https://access.redhat.com/security/cve/CVE-2026-48526https://access.redhat.com/security/cve/CVE-2026-48746https://access.redhat.com/security/cve/CVE-2026-54283https://access.redhat.com/security/cve/CVE-2026-8643https://access.redhat.com/security/updates/classification/https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.6/whats_new-async_updatesCanonical URLhttps://access.redhat.com/errata/RHSA-2026:34773https://www.redhat.com/en/products/aiCanonical URLReference 21Reference 22Reference 23Reference 24Reference 25Reference 26Reference 27Reference 28Reference 29Reference 30Reference 31Reference 32Reference 33Reference 34Reference 35Reference 36Reference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47Reference 48Reference 49Reference 50Reference 51Reference 52Reference 53Reference 54Reference 55Reference 56https://access.redhat.com/security/cve/CVE-2026-11332https://access.redhat.com/security/cve/CVE-2026-13149https://access.redhat.com/security/cve/CVE-2026-13676https://access.redhat.com/security/cve/CVE-2026-18141https://access.redhat.com/security/cve/CVE-2026-34993https://access.redhat.com/security/cve/CVE-2026-40898https://access.redhat.com/security/cve/CVE-2026-44545https://access.redhat.com/security/cve/CVE-2026-48990https://access.redhat.com/security/cve/CVE-2026-54058https://access.redhat.com/security/cve/CVE-2026-54060https://access.redhat.com/security/cve/CVE-2026-55379https://access.redhat.com/security/cve/CVE-2026-55380https://access.redhat.com/security/cve/CVE-2026-59197https://access.redhat.com/security/cve/CVE-2026-59869https://access.redhat.com/security/cve/CVE-2026-59886https://access.redhat.com/security/cve/CVE-2026-59939https://access.redhat.com/security/cve/CVE-2026-9595Canonical URLCanonical URLReference 76Canonical URLCanonical URLCanonical URLhttps://access.redhat.com/security/updates/classification/#importantCanonical URLhttps://images.redhat.com/Canonical URLCanonical URLCanonical URLCanonical URLCanonical URLhttps://access.redhat.com/security/cve/CVE-2026-42215https://access.redhat.com/security/cve/CVE-2026-42284https://access.redhat.com/security/cve/CVE-2026-44244Canonical URLReference 92Canonical URLReference 94Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses