PT-2026-51010 · Awx · Awx

·

CVE-2026-12726

·

Published

2026-06-19

·

Updated

2026-06-20

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AWX (affected versions not specified)
Description A flaw exists in the GitHub webhook integration where the controller stores the pull request.statuses url value from a pull request webhook payload without validating if it points to a trusted GitHub API endpoint. If a job template uses a GitHub Personal Access Token (PAT) as its webhook credential, the controller sends this token to the stored callback URL during job status updates. An attacker capable of submitting a signed forged webhook using the webhook key can redirect the callback to a malicious URL to exfiltrate the GitHub PAT.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12726

Affected Products

Awx