CVE-2016-7070: Red Hat Ansible Tower

High severity, CVSS 8.0. EPSS: 0.6% chance of exploitation in the next 30 days.

A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the database.

Affected products

  • Red Hat Ansible Tower: before 3.0.3 (fixed in 3.0.3)

Published 2018-09-11. Last modified 2026-06-17.