CVE-2026-75884: Red Hat Ansible Automation Platform 2.4 For Rhel 8
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
Affected products
- Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 8: before 0:4.5.36-1.el8ap (fixed in 0:4.5.36-1.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.4 For Rhel 9: before 0:4.5.36-1.el9ap (fixed in 0:4.5.36-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 8: before 0:4.6.33-1.el8ap (fixed in 0:4.6.33-1.el8ap)
- Red Hat Red Hat Ansible Automation Platform 2.5 For Rhel 9: before 0:4.6.33-1.el9ap (fixed in 0:4.6.33-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.6: before 1789673739 (fixed in 1789673739)
- Red Hat Red Hat Ansible Automation Platform 2.6 For Rhel 9: before 0:4.7.17-1.el9ap (fixed in 0:4.7.17-1.el9ap)
- Red Hat Red Hat Ansible Automation Platform 2.7: before 1789580684 (fixed in 1789580684)
Published 2026-09-23. Last modified 2026-09-24.