CVE-2026-6266
8.3Red Hat · Ansible Automation Platform (AAP)
A flaw in the AAP gateway user auto-link strategy allows remote attackers to hijack accounts via unverified email matching.
Executive summary
An authentication bypass vulnerability in the Red Hat Ansible Automation Platform gateway allows authenticated attackers to hijack victim accounts and gain elevated privileges.
Vulnerability
This is an authentication bypass flaw categorized under CWE-305, where the user auto-link strategy automatically connects external Identity Provider identities to existing accounts using unverified email matching, requiring low privileges to exploit over the network.
Business impact
A successful exploit permits unauthorized users to hijack existing accounts, potentially acquiring administrative privileges over the automation infrastructure. This compromises the confidentiality, integrity, and availability of managed systems and sensitive operational data. The high CVSS score of 8.3 reflects the severe risk of privilege escalation and complete control over automation workflows.
Remediation
Immediate Action: Apply the vendor security updates provided in Red Hat errata RHSA-2026:13508, RHSA-2026:13512, and RHSA-2026:13545 to update the affected components immediately.
Proactive Monitoring: Monitor authentication logs for unusual account linking events, unexpected privilege changes, and anomalous API access patterns.
Compensating Controls: Implement strict monitoring of Identity Provider configurations and restrict network access to the gateway interface where feasible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity rating and the potential for complete account and administrative takeover, administrators must prioritize patching. Update all vulnerable instances of the Ansible Automation Platform to the fixed versions immediately to secure federated authentication pathways.
More Red Hat CVEs
Sources
Originally found and disclosed by This issue was discovered by Robin Bobbitt (Red Hat)., per the CVE Program record.
- RHSA-2026:13508 Vendor advisory
- RHSA-2026:13512 Vendor advisory
- RHSA-2026:13545 Vendor advisory
- Vulnerability database entry
- RHBZ#2458142 Issue tracker