Description
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
Published: 2026-09-23
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the AWX component of Red Hat Ansible Automation Platform 2, where the pod_spec_override field in container groups implements an incomplete blocklist that permits injection of initContainers, serviceAccountName overrides, and projected service account token volumes. This flaw allows an attacker who gains administrator access to the AAP platform to craft malicious pod specifications that execute with elevated privileges, effectively escalating to OpenShift namespace‑level authority and enabling exfiltration of secrets stored in that namespace. The weakness is identified as CWE‑184.

Affected Systems

Red Hat Ansible Automation Platform 2 is affected. All installations of AAP 2 that expose the AWX web interface or API with the pod_spec_override functionality active are vulnerable; no specific minor version ranges are listed, so the entire product line 2 requires scrutiny.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity, and the EPSS score is not available, implying no publicly held data on exploitation frequency but still warranting concern. The vulnerability is not listed in CISA KEV, but its high score and direct impact on OpenShift namespaces suggest a significant risk if exploited. The likely attack vector is an account with AAP administrative privileges that submits a pod specification containing malicious overrides. Once injected, the attacker can gain namespace‑level access and read or export secrets, compromising confidentiality and potentially enabling further lateral movement within the cluster.

Generated by OpenCVE AI on September 23, 2026 at 20:22 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Apply the latest Red Hat Ansible Automation Platform 2 update that fixes pod_spec_override injection
  • If a patch is not yet available, disable or restrict the pod_spec_override configuration so that only approved fields are accepted
  • Limit administrative privileges on the AAP platform and monitor logs for suspicious pod_spec_override activity

Generated by OpenCVE AI on September 23, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat ansible Automation Platform Developer
CPEs cpe:/a:redhat:ansible_automation_platform:2.4::el8
cpe:/a:redhat:ansible_automation_platform:2.4::el9
cpe:/a:redhat:ansible_automation_platform_developer:2.4::el8
cpe:/a:redhat:ansible_automation_platform_developer:2.4::el9
Vendors & Products Redhat ansible Automation Platform Developer
References

Wed, 23 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
Title Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups
First Time appeared Redhat
Redhat ansible Automation Platform
Weaknesses CWE-184
CPEs cpe:/a:redhat:ansible_automation_platform:2
Vendors & Products Redhat
Redhat ansible Automation Platform
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Redhat Ansible Automation Platform Ansible Automation Platform Developer
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-23T21:45:44.016Z

Reserved: 2026-08-18T13:12:40.303Z

Link: CVE-2026-75884

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T20:17:14.637

Modified: 2026-09-23T20:17:14.637

Link: CVE-2026-75884

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T20:30:09Z

Weaknesses
  • CWE-184

    Incomplete List of Disallowed Inputs