A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | Upgrade aap-metrics-utilityUpgrade automation-controllerUpgrade automation-eda-controller-base-servicesUpgrade automation-gateway-proxy-debugsourceUpgrade python3.12-django-ansible-base+rest_filtersUpgrade automation-gateway-proxy-serverUpgrade automation-platform-uiUpgrade automation-eda-controllerUpgrade automation-eda-controller-baseUpgrade python3.12-django-ansible-base+feature_flagsUpgrade automation-controller-venv-towerUpgrade receptor-debugsourceUpgrade python3.12-django-ansible-base+channel_authUpgrade python3.12-django-ansible-base+resource_registryUpgrade python3.12-gitpythonUpgrade python3.12-galaxy-ngUpgrade python3.12-django-ansible-base+jwt_consumerUpgrade automation-gateway-proxyUpgrade automation-gateway-serverUpgrade python3.12-django-ansible-base+authenticationUpgrade automation-gatewayUpgrade receptorUpgrade python3.12-django-ansible-base+redis_clientUpgrade automation-controller-cliUpgrade automation-hubUpgrade python3.12-django-ansible-base+rbacUpgrade python3.12-sqlparseUpgrade python3.12-django-ansible-base+oauth2_providerUpgrade automation-eda-controller-event-stream-servicesUpgrade automation-controller-uiUpgrade receptor-debuginfoUpgrade automation-controller-serverUpgrade automation-gateway-proxy-server-debuginfoUpgrade python3.12-django-ansible-base+api_documentationUpgrade automation-eda-controller-worker-servicesUpgrade python3-sqlparseUpgrade python3.12-django-ansible-base+activitystreamUpgrade python3.12-django-ansible-baseUpgrade automation-gateway-configUpgrade receptorctl | Sep 25, 2026 | Sep 23, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub