Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-11807: Event-Driven Ansible Websocket API Missing Authorization

CVE-2026-11807 CVE-2026-11807
Summary

An unauthorized user can access sensitive credentials of other users by sending a malicious message. This is a serious security risk because it can lead to unauthorized access to important systems and data. To protect your systems, update to the latest version of Event-Driven Ansible.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
red hat red hat ansible automation platform 2.5 for rhel 8 All versions
red hat red hat ansible automation platform 2.5 for rhel 9 All versions
red hat red hat ansible automation platform 2.6 for rhel 9 All versions
red hat red hat ansible automation platform 2.5 All versions
red hat red hat ansible automation platform 2.6 All versions
red hat red hat ansible automation platform 2.7 All versions
Original title
Eda-server: websocket missing authorization allows credential theft via activation_id spoofing
Original description
A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys.
nvd CVSS3.1 9.6
Vulnerability type
CWE-862 Missing Authorization
Published: 23 Jun 2026 · Updated: 23 Jul 2026 · First seen: 23 Jun 2026