CVE-2026-6266

8.3

Red Hat · Ansible Automation Platform (AAP)

A flaw in the AAP gateway user auto-link strategy allows remote attackers to hijack accounts via unverified email matching.

Executive summary

An authentication bypass vulnerability in the Red Hat Ansible Automation Platform gateway allows authenticated attackers to hijack victim accounts and gain elevated privileges.

Vulnerability

This is an authentication bypass flaw categorized under CWE-305, where the user auto-link strategy automatically connects external Identity Provider identities to existing accounts using unverified email matching, requiring low privileges to exploit over the network.

Business impact

A successful exploit permits unauthorized users to hijack existing accounts, potentially acquiring administrative privileges over the automation infrastructure. This compromises the confidentiality, integrity, and availability of managed systems and sensitive operational data. The high CVSS score of 8.3 reflects the severe risk of privilege escalation and complete control over automation workflows.

Remediation

Immediate Action: Apply the vendor security updates provided in Red Hat errata RHSA-2026:13508, RHSA-2026:13512, and RHSA-2026:13545 to update the affected components immediately.

Proactive Monitoring: Monitor authentication logs for unusual account linking events, unexpected privilege changes, and anomalous API access patterns.

Compensating Controls: Implement strict monitoring of Identity Provider configurations and restrict network access to the gateway interface where feasible.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity rating and the potential for complete account and administrative takeover, administrators must prioritize patching. Update all vulnerable instances of the Ansible Automation Platform to the fixed versions immediately to secure federated authentication pathways.

More Red Hat CVEs

Sources

Originally found and disclosed by This issue was discovered by Robin Bobbitt (Red Hat)., per the CVE Program record.