CVE-2026-12701: Red Hat Ansible Automation Platform 2

Critical severity, CVSS 9.0. EPSS: 1.2% chance of exploitation in the next 30 days.

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but fails to block directory traversal sequences such as "../" anywhere in the path. An authenticated administrator can craft a relative_path containing embedded traversal sequences (e.g., "looking/normal/../../../../etc/shadow") that escapes the intended export directory during FilesystemExport operations. Because the file content is also user-controlled (uploaded artifact), this allows arbitrary file write to any location writable by the Pulp service user, potentially leading to service compromise or further system exploitation.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:3.49.63-2.el8ap (fixed in 0:3.49.63-2.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:3.49.63-2.el9ap (fixed in 0:3.49.63-2.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.6: before 1783979593 (fixed in 1783979593)
  • Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:3.49.63-2.el9ap (fixed in 0:3.49.63-2.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.7: before 1783919521 (fixed in 1783919521)
  • Red Hat Red Hat Satellite 6.16 For Rhel 8: before 0:3.49.39-2.el8pc (fixed in 0:3.49.39-2.el8pc)
  • Red Hat Red Hat Satellite 6.16 For Rhel 9: before 0:3.49.39-2.el9pc (fixed in 0:3.49.39-2.el9pc)
  • Red Hat Red Hat Satellite 6.17 For Rhel 9: before 0:3.63.21-2.el9pc (fixed in 0:3.63.21-2.el9pc)
  • Red Hat Red Hat Satellite 6.18 For Rhel 9: before 0:3.73.30-2.el9pc (fixed in 0:3.73.30-2.el9pc)
  • Red Hat Red Hat Satellite 6.19 For Rhel 9: before 0:3.85.15-5.el9pc (fixed in 0:3.85.15-5.el9pc)
  • Red Hat Red Hat Update Infrastructure 4 For Cloud Providers
  • Red Hat Red Hat Update Infrastructure 5

Published 2026-07-20. Last modified 2026-07-22.