Authorization Bypass in Ansible Automation Platform Gateway
CVE-2026-94416
6.8MEDIUM
What is CVE-2026-94416?
The Ansible Automation Platform gateway suffers from an authorization bypass issue that allows an authenticated administrator to create service keys without proper restrictions, leading to potential impersonation of the Controller service. This vulnerability could enable an attacker to forge service-authentication tokens, facilitating unauthorized access to sensitive workloads. When exploited in conjunction with the gateway's OIDC workload-identity endpoint, it poses a significant risk of credential exposure from downstream services, such as HashiCorp Vault, which may accept these forged tokens, effectively breaching security boundaries.