Impact
An authorization bypass has been discovered in the Ansible Automation Platform gateway. The gateway API allows any authenticated administrator to create a new service key for the Controller service cluster, but the creation is not limited to installer‑provisioned keys. As a result, an administrator‑issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service‑authentication token that impersonates the Controller service. When combined with the gateway OIDC workload‑identity endpoint, an attacker can have the gateway sign Workload Identity Tokens for arbitrary Controller workloads. A downstream resource server (such as HashiCorp Vault) that trusts the gateway OIDC key will accept the forged token and return the AAP credentials bound to that workload, thereby disclosing secrets beyond the attacker’s authorized scope.
Affected Systems
The vulnerability affects Red Hat Ansible Automation Platform 2, including all instances of the product listed in the CNA entries.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. EPSS data is currently unavailable and the issue is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The attack vector is likely to be local to administrators who have access to the gateway API, but an attacker could craft a forged token that would be accepted by trusted downstream services, exposing stored secrets.
OpenCVE Enrichment