CVE-2026-6266: Red Hat Ansible Automation Platform 2.5 For Rhel 8
High severity, CVSS 8.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or gain unauthorized access to other accounts, including administrative accounts, by manipulating the IDP-provided email.
Affected products
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.28-3.el8ap (fixed in 0:4.6.28-3.el8ap); before 0:2.5.20260422-2.el8ap (fixed in 0:2.5.20260422-2.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.28-3.el9ap (fixed in 0:4.6.28-3.el9ap); before 0:2.5.20260422-2.el9ap (fixed in 0:2.5.20260422-2.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.6: before 1777377014 (fixed in 1777377014); before 1777311120 (fixed in 1777311120)
- Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.11-2.el9ap (fixed in 0:4.7.11-2.el9ap); before 0:2.6.20260422-1.el9ap (fixed in 0:2.6.20260422-1.el9ap)
Published 2026-05-04. Last modified 2026-08-26.