Description
A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.
Published: 2026-08-24
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery with credential leakage
Action: Apply patch immediately
AI Analysis

Impact

The vulnerability is a server‑side request forgery in several AWX notification backends, such as webhook, Mattermost, Rocket.Chat, and Grafana. The backends use notification template URLs as direct HTTP request targets without validating whether the target address is a private, loopback, or reserved IP range. An organization notification administrator can therefore create or modify templates that point to internal or loopback addresses, which causes the AWX control node to issue HTTP requests to services that are not externally reachable. In addition, the webhook backend follows HTTP redirects and re‑sends configured Basic Authentication credentials to the redirect target regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker‑controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL, further exposing sensitive credentials. This combination enables an attacker to gain confidential information and potentially access internal systems.

Affected Systems

The affected product is Red Hat Ansible Automation Platform 2, the AWX component that runs the notification backends. The CNA list does not specify more granular version information; all instances of the platform are considered vulnerable.

Risk and Exploitability

The CVSS score of 7.7 indicates a moderate‑to‑high severity bug. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation yet. The likely attack vector requires an attacker to have sufficient privileges to create or modify notification templates, which usually means a trusted administrator. Once such privileges are exercised, the attacker can load internal services or redirect requests to move confidential credentials outside the network, posing a substantial confidentiality risk. The absence of a public exploit at the time of analysis does not mitigate the likelihood that a motivated adversary with admin access could leverage the flaw.

Generated by OpenCVE AI on August 24, 2026 at 19:43 UTC.

Remediation

Vendor Workaround

There is no complete mitigation for this vulnerability other than applying the update when available. However, the following measures reduce exposure: 1. Restrict the ability to create and modify notification templates to trusted administrators who have legitimate need for this capability. 2. Implement network egress filtering on the Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local (169.254.0.0/16) address ranges. 3. Monitor notification template configurations for URLs pointing to internal or unusual addresses. 4. Avoid configuring sensitive credentials (Basic Auth, Grafana API keys) in notification templates until the fix is applied. Use notification backends that do not require credentials where possible. 5. Review and audit existing notification templates for URLs pointing to internal services.


OpenCVE Recommended Actions

  • Apply the vendor‑provided update for Red Hat Ansible Automation Platform 2 as soon as it becomes available.
  • Restrict the ability to create and modify notification templates to trusted administrators who have a legitimate need.
  • Implement network egress filtering on the Automation Controller nodes to block outbound connections to loopback (127.0.0.0/8), private (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link‑local (169.254.0.0/16) address ranges.
  • Monitor notification template configurations for URLs pointing to internal or unusual addresses.
  • Avoid configuring sensitive credentials (Basic Auth, Grafana API keys) in notification templates until the fix is applied and use backends that do not require credentials where possible.
  • Review and audit existing notification templates for URLs pointing to internal services.

Generated by OpenCVE AI on August 24, 2026 at 19:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Tue, 25 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:ansible_automation_platform:2.7::el9
References

Mon, 24 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform Developer
Redhat ansible Automation Platform Inside
CPEs cpe:/a:redhat:ansible_automation_platform:2.5::el8
cpe:/a:redhat:ansible_automation_platform:2.5::el9
cpe:/a:redhat:ansible_automation_platform:2.6::el10
cpe:/a:redhat:ansible_automation_platform:2.6::el9
cpe:/a:redhat:ansible_automation_platform_developer:2.5::el8
cpe:/a:redhat:ansible_automation_platform_developer:2.5::el9
cpe:/a:redhat:ansible_automation_platform_developer:2.6::el10
cpe:/a:redhat:ansible_automation_platform_developer:2.6::el9
cpe:/a:redhat:ansible_automation_platform_inside:2.6::el9
Vendors & Products Redhat ansible Automation Platform Developer
Redhat ansible Automation Platform Inside
References

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability was found in multiple AWX notification backends. The webhook, Mattermost, Rocket.Chat, and Grafana notification backends use notification template URLs as direct HTTP request targets without validating the target address against private, loopback, or reserved IP ranges. An organization notification administrator can create notification templates pointing to internal or loopback addresses, causing the AWX control node to issue HTTP requests to services that are not externally accessible. Additionally, the webhook notification backend follows HTTP redirects and resends configured Basic Authentication credentials to redirect targets regardless of host change, allowing an attacker to exfiltrate notification credentials by redirecting to an attacker-controlled host. The Grafana backend sends its API key in the Authorization header to the configured target URL.
Title Awx: notification backends allow ssrf and credential leakage
First Time appeared Redhat
Redhat ansible Automation Platform
Weaknesses CWE-918
CPEs cpe:/a:redhat:ansible_automation_platform:2
Vendors & Products Redhat
Redhat ansible Automation Platform
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Redhat Ansible Automation Platform Ansible Automation Platform Developer Ansible Automation Platform Inside
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-26T18:26:31.611Z

Reserved: 2026-08-06T04:27:34.372Z

Link: CVE-2026-71366

cve-icon Vulnrichment

Updated: 2026-08-26T18:26:27.829Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-24T16:17:22.820

Modified: 2026-08-28T21:17:10.720

Link: CVE-2026-71366

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-24T15:00:57Z

Links: CVE-2026-71366 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T19:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)