PT-2026-1730 · Red Hat · Ansible Automation Platform

CVE-2025-14025

·

Publicado

2026-01-08

·

Atualizado

2026-01-08

CVSS v3.1

8.5

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ansible Automation Platform (AAP) (affected versions not specified)
Description A flaw exists in Ansible Automation Platform (AAP) where read-only scoped OAuth2 API Tokens, enforced at the Gateway level for Gateway-specific operations, can be used to perform write operations on backend services such as the Controller, Hub, and EDA. Exploitation of this issue could allow an attacker’s capabilities to be limited only by role based access controls (RBAC).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14025
RHSA-2026:0360
RHSA-2026:0361

Produtos afetados

Ansible Automation Platform