Vulnerability in HashiCorp Vault Credential Plugin for AAP Controller by Red Hat
CVE-2026-12564
What is CVE-2026-12564?
A flaw exists within the HashiCorp Vault credential plugin used in the AAP Controller. Specifically, the kubernetes_auth() function in awx_plugins/credentials/hashivault.py is susceptible to exfiltration of the Kubernetes service account token. This occurs when an authenticated attacker with sufficient privileges tests a HashiCorp Vault Secret Lookup credential configured for kubernetes_role authentication. By redirecting the service account token to a malicious URL, an attacker can gain unauthorized access to the Kubernetes API. This access allows for full control over pod operations and the ability to read secrets, including sensitive information such as database credentials and the Django SECRET_KEY, potentially compromising the entire control plane.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved