Server-Side Request Forgery Vulnerability in AWX Notification Backends by Red Hat
CVE-2026-71366

7.7HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
24 August 2026

What is CVE-2026-71366?

A server-side request forgery vulnerability exists in AWX notification backends, including Mattermost, Rocket.Chat, and Grafana. This issue arises when notification template URLs are utilized as direct HTTP request targets without proper validation against internal, loopback, or reserved IP ranges. As a result, notification administrators can craft templates that point to internal resources, enabling the AWX control node to send HTTP requests to services that are normally inaccessible from outside the network. Moreover, the webhook notification backend can follow HTTP redirects, potentially exposing Basic Authentication credentials to an attacker by redirecting to malicious hosts. Additionally, the Grafana notification backend transmits its API key through the Authorization header to designed target URLs, heightening the risk of credential exfiltration.

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.