Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.7

Red Hat Ansible Automation Platform exposes sensitive credentials and infrastructure info

CVE-2025-9907
Summary

The Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA) Event Stream API has a flaw that could leak sensitive information, potentially exposing internal infrastructure details, user or system credentials, and high-value tokens. This could allow unauthorized access and put your data at risk. To protect your system, update the Red Hat Ansible Automation Platform as soon as possible.

Original title
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastruct...
Original description
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
nvd CVSS3.1 6.7
Vulnerability type
CWE-200 Information Exposure
Published: 27 Feb 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026