Vulnerability in HashiCorp Vault Credential Plugin for AAP Controller by Red Hat
CVE-2026-12564

9.6CRITICAL

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
18 August 2026

What is CVE-2026-12564?

A flaw exists within the HashiCorp Vault credential plugin used in the AAP Controller. Specifically, the kubernetes_auth() function in awx_plugins/credentials/hashivault.py is susceptible to exfiltration of the Kubernetes service account token. This occurs when an authenticated attacker with sufficient privileges tests a HashiCorp Vault Secret Lookup credential configured for kubernetes_role authentication. By redirecting the service account token to a malicious URL, an attacker can gain unauthorized access to the Kubernetes API. This access allows for full control over pod operations and the ability to read secrets, including sensitive information such as database credentials and the Django SECRET_KEY, potentially compromising the entire control plane.

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Chris Meyers (Red Hat).
.