Authorization Bypass in Ansible Automation Platform Gateway
CVE-2026-94416

6.8MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
24 September 2026

What is CVE-2026-94416?

The Ansible Automation Platform gateway suffers from an authorization bypass issue that allows an authenticated administrator to create service keys without proper restrictions, leading to potential impersonation of the Controller service. This vulnerability could enable an attacker to forge service-authentication tokens, facilitating unauthorized access to sensitive workloads. When exploited in conjunction with the gateway's OIDC workload-identity endpoint, it poses a significant risk of credential exposure from downstream services, such as HashiCorp Vault, which may accept these forged tokens, effectively breaching security boundaries.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.