CVE-2026-71366

7.7

Red Hat · Ansible Automation Platform

A server-side request forgery (SSRF) vulnerability exists in multiple AWX notification backends within the Red Hat Ansible Automation Platform.

Executive summary

A server-side request forgery vulnerability in Red Hat Ansible Automation Platform notification backends allows authenticated attackers to force the server to send unauthorized requests to internal resources.

Vulnerability

This SSRF vulnerability (CWE-918) originates in the AWX notification backends. An authenticated attacker can manipulate these backends to perform requests against arbitrary internal network locations.

Business impact

The ability to perform SSRF allows attackers to probe internal networks that are otherwise protected by a firewall or network perimeter. With a CVSS score of 7.7, this poses a high risk to the internal infrastructure, potentially enabling the discovery of internal services, credentials, or metadata endpoints. This could lead to a broader compromise of the automation environment.

Remediation

Immediate Action: Apply the vendor-provided security updates: upgrade to version 4.6.32-1.el8ap (2.5/RHEL 8), 4.6.32-1.el9ap (2.5/RHEL 9), or 4.7.16-1.el9ap (2.6/RHEL 9).

Proactive Monitoring: Monitor network egress logs from the Ansible Automation Platform server to detect connections to unauthorized or unexpected internal IP addresses.

Compensating Controls: Restrict outbound network access from the Ansible server to only essential external services, effectively limiting the scope of any potential SSRF.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for network reconnaissance and internal service exploitation, it is critical to apply the provided patches immediately. Organizations should prioritize updating their Ansible Automation Platform deployments to prevent unauthorized internal network access.

More Red Hat CVEs