PT-2026-51010 · Red Hat · Red Hat Ansible Automation Platform 2

Publicado

2026-06-19

·

Atualizado

2026-06-19

·

CVE-2026-12726

CVSS v3.1

6.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull request webhooks, the controller stores the pull request.statuses url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged webhook using the job template's webhook key can redirect the callback to an attacker-controlled URL and exfiltrate the configured GitHub PAT.

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-12726

Produtos afetados

Red Hat Ansible Automation Platform 2