PT-2026-80906 · Awx+3 · Awx+3

CVE-2026-71366

·

Published

2026-08-24

·

Updated

2026-08-25

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AWX (affected versions not specified)
Description A server-side request forgery (SSRF) issue exists in the webhook, Mattermost, Rocket.Chat, and Grafana notification backends. These backends use notification template URLs as direct HTTP request targets without validating the address against private, loopback, or reserved IP ranges. This allows an organization notification administrator to create templates that force the AWX control node to send HTTP requests to internal services that are not externally accessible. Furthermore, the webhook backend follows HTTP redirects and resends Basic Authentication credentials to the redirect target even if the host changes, which can lead to credential exfiltration. The Grafana backend also sends its API key in the Authorization header to the configured target URL.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71366

Affected Products

Awx
Grafana
Mattermost
Rocket.Chat