CVE-2026-11807: Red Hat Ansible Automation Platform 2.5

Critical severity, CVSS 9.6. EPSS: 0.5% chance of exploitation in the next 30 days.

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2.5: before 1781741251 (fixed in 1781741251)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:1.1.19-1.el8ap (fixed in 0:1.1.19-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:1.1.19-1.el9ap (fixed in 0:1.1.19-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.6: before 1781732675 (fixed in 1781732675)
  • Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:1.2.9-2.el9ap (fixed in 0:1.2.9-2.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.7: before 1781730525 (fixed in 1781730525)

Published 2026-06-23. Last modified 2026-07-16.