PT-2026-51010 · Red Hat · Red Hat Ansible Automation Platform 2

Martin Brodeur

·

Published

2026-06-19

·

Updated

2026-06-19

·

CVE-2026-12726

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull request webhooks, the controller stores the pull request.statuses url value from the webhook payload without validating that it points to a trusted GitHub API endpoint. If a job template is configured with a GitHub Personal Access Token as its webhook credential, the controller later POSTs that token to the stored callback URL when posting job status updates. An attacker who can submit a correctly signed forged webhook using the job template's webhook key can redirect the callback to an attacker-controlled URL and exfiltrate the configured GitHub PAT.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12726

Affected Products

Red Hat Ansible Automation Platform 2