PT-2026-51010 · Red Hat · Red Hat Ansible Automation Platform 2
Martin Brodeur
·
Published
2026-06-19
·
Updated
2026-06-19
·
CVE-2026-12726
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull request webhooks, the controller stores the pull request.statuses url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged webhook using the job template's webhook key can redirect the callback to an attacker-controlled URL and exfiltrate the configured GitHub PAT.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Ansible Automation Platform 2