Threats Tagged 'cve-2026-6266'
View all threats tagged with 'cve-2026-6266'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-6266'
Click on any threat for detailed analysis and mitigation recommendations
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Product Security and Bug Fix UpdateCVE-2025-14550 0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Account hijacking and unauthorized access via unverified email linking (CVE-2026-6266) * automation-controller: DTLS cookie callback buffer overflow (CVE-2026-27459) * automation-controller: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) (CVE-2026-32597) * automation-controller: denial of service via malformed HTML-like sequences (CVE-2025-69534) * automation-gateway: Account hijacking and unauthorized access via unverified email linking (CVE-2026-6266) * automation-gateway-proxy: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * automation-platform-ui: Rollup: Remote Code Execution via Path Traversal Vulnerability (CVE-2026-27606) * automation-platform-ui: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996) * python3.12-django-ansible-base: Account hijacking and unauthorized access via unverified email linking (CVE-2026-6266) * python3.12-markdown: denial of service via malformed HTML-like sequences (CVE-2025-69534) * python3.12-jwcrypto: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373) * python3.12-pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922) * python3.12-pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) * python3.12-pyOpenSSL: DTLS cookie callback buffer overflow (CVE-2026-27459) * receptor: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 05/04/2026, 14:10:09 UTC Added: 05/26/2026, 20:58:34 UTC |
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Product Security and Bug Fix UpdateCVE-2025-69534 0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): * automation-controller: Account hijacking and unauthorized access via unverified email linking (CVE-2026-6266) * automation-controller: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) (CVE-2026-32597) * automation-controller: denial of service via malformed HTML-like sequences (CVE-2025-69534) * automation-controller: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves (CVE-2026-26007) * automation-gateway: Account hijacking and unauthorized access via unverified email linking (CVE-2026-6266) * automation-gateway: Rollup: Remote Code Execution via Path Traversal Vulnerability (CVE-2026-27606) * automation-gateway: SVGO: Denial of Service via XML entity expansion (CVE-2026-29074) * automation-gateway: ReDoS via $data reference (CVE-2025-69873) * automation-gateway-proxy: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * python3.12-django-ansible-base: Account hijacking and unauthorized access via unverified email linking (CVE-2026-6266) * python3.12-markdown: denial of service via malformed HTML-like sequences (CVE-2025-69534) * python3.12-jwcrypto: JWCrypto: Memory exhaustion via crafted compressed JWE tokens (CVE-2026-39373) * python3.12-pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion (CVE-2026-30922) * python3.12-pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID (CVE-2026-23490) * python3.12-pyOpenSSL: DTLS cookie callback buffer overflow (CVE-2026-27459) * receptor: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 05/04/2026, 14:31:09 UTC Added: 05/26/2026, 20:58:34 UTC |
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release UpdateCVE-2025-68121 0 Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. For details about this release, refer to the release notes listed in the References section. Join the discussion | GCVE Database | 05/04/2026, 17:14:54 UTC Added: 05/26/2026, 20:58:28 UTC |
Red Hat Security Advisory: RHTAS 1.3.4 - Red Hat Trusted Artifact Signer ReleaseCVE-2025-68121 0 The RHTAS Operator can be used with OpenShift Container Platform 4.16, 4.17, 4.18, 4.19, 4.20 and 4.21 Join the discussion | GCVE Database | 04/23/2026, 12:15:28 UTC Added: 05/26/2026, 20:57:58 UTC |
CVE-2026-6266: Authentication Bypass by Primary Weakness in Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8CVE-2026-6266 0 CVE-2026-6266 is a vulnerability in Red Hat Ansible Automation Platform 2.5 and 2.6 where the user auto-link strategy introduced in version 2.6 automatically links an external Identity Provider (IDP) identity to an existing user account based on email matching without verifying email ownership. This flaw allows a remote attacker to potentially hijack victim accounts or gain unauthorized access to other accounts, including administrative ones, by manipulating the IDP-provided email. The vulnerability has a CVSS score of 8.3 (high severity). Red Hat has released security updates for Ansible Automation Platform 2.5 and 2.6 to address this issue. Join the discussion | CVE Database V5 | 05/04/2026, 13:47:07 UTC Added: 05/04/2026, 14:21:33 UTC |
Showing 1 to 5 of 5 results