PT-2026-63337 · Red Hat · Red Hat Ansible Automation Platform 2

CVE-2026-16544

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer access() function (job events, workflow events, ad hoc command events). Three event groups - inventory update events, project update events, and system job events — are not mapped, causing the authorization check to be skipped. Any authenticated user can subscribe to these unmapped websocket event groups for any object ID and receive real-time stdout output from jobs belonging to organizations they have no access to. This is an incomplete remediation of CVE-2020-10698.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16544

Affected Products

Red Hat Ansible Automation Platform 2