CVE-2026-12564 – Red Hat Ansible Automation Platform 2
“A crafted Vault credential can expose the controller’s Kubernetes identity and open access to sensitive control-plane resources.”
Red Hat addresses a Critical server-side request forgery vulnerability in the Ansible Automation Platform Controller HashiCorp Vault credential plugin. CVE-2026-12564 allows an authenticated attacker with credential-creation privileges to send the controller pod’s Kubernetes service account token to an attacker-controlled endpoint. The stolen token can provide Kubernetes API access to control-plane namespaces, including pod management and access to sensitive secrets such as database credentials and the Django SECRET_KEY. The CVSS score is 9.6, which is Critical severity.
Red Hat has released security updates for affected Ansible Automation Platform branches, including versions 2.6 and 2.7.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- Low
- User Interaction
- None
- CWE Classification
- CWE-918