Skip to finding
important · Privilege escalation

Read-only Ansible job-template access can launch stored automation against arbitrary managed hosts.

Affects

Red Hat Ansible Automation Platform automation-controller on RHEL and OpenShift, which runs stored jobs across managed infrastructure.

With AAP behind its gateway and the proxy allow-list empty, a template viewer can read the provisioning callback key, spoof X-Forwarded-For and launch the stored template against an attacker-selected inventory host using saved credentials. Red Hat has shipped updates.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026