CVE-2026-52902: Red Hat Ansible Automation Platform 2
Medium severity, CVSS 4.7. EPSS: 0.2% chance of exploitation in the next 30 days.
A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.
Affected products
- Red Hat Red Hat Ansible Automation Platform 2
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.32-1.el8ap (fixed in 0:4.6.32-1.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.32-1.el9ap (fixed in 0:4.6.32-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.16-1.el9ap (fixed in 0:4.7.16-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.7 For Rhel 10: before 0:4.8.6-1.el10ap (fixed in 0:4.8.6-1.el10ap)
- Red Hat Red Hat Ansible Automation Platform 2.7 For Rhel 9: before 0:4.8.6-1.el9ap (fixed in 0:4.8.6-1.el9ap)
Published 2026-06-09. Last modified 2026-08-24.