CVE-2026-52902: Red Hat Ansible Automation Platform 2

Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.

Affected products

  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.32-1.el8ap (fixed in 0:4.6.32-1.el8ap)
  • Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.32-1.el9ap (fixed in 0:4.6.32-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.16-1.el9ap (fixed in 0:4.7.16-1.el9ap)
  • Red Hat Red Hat Ansible Automation Platform 2.7 For Rhel 10: before 0:4.8.6-1.el10ap (fixed in 0:4.8.6-1.el10ap)
  • Red Hat Red Hat Ansible Automation Platform 2.7 For Rhel 9: before 0:4.8.6-1.el9ap (fixed in 0:4.8.6-1.el9ap)

Published 2026-06-09. Last modified 2026-08-24.