PT-2026-97791 · Red Hat · Ansible Automation Platform
CVE-2026-94416
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ansible Automation Platform (affected versions not specified)
Description
An authorization bypass exists in the gateway API that allows an authenticated administrator to create a new service key for the Controller service cluster. Since this process is not restricted to the installer-provisioned path, the resulting key can be used to forge a service-authentication token to impersonate the Controller service. When the gateway OIDC workload-identity endpoint is enabled via
FEATURE OIDC WORKLOAD IDENTITY ENABLED, an attacker can force the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. Consequently, a downstream resource server trusting the gateway OIDC key may accept the forged WIT and disclose secrets bound to that workload.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform