CVE-2026-75884 PUBLISHED

Awx: awx: privilege escalation to openshift namespace via pod_spec_override injection in container groups

Assigner: redhat
Reserved: 18.08.2026 Published: 23.09.2026 Updated: 24.09.2026

A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.1

Product Status

Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.4 for RHEL 8
Versions Default: affected
  • unaffected from 0:4.5.36-1.el8ap to * (excl.)
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.4 for RHEL 9
Versions Default: affected
  • unaffected from 0:4.5.36-1.el9ap to * (excl.)
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.5 for RHEL 8
Versions Default: affected
  • unaffected from 0:4.6.33-1.el8ap to * (excl.)
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.5 for RHEL 9
Versions Default: affected
  • unaffected from 0:4.6.33-1.el9ap to * (excl.)
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.6 for RHEL 9
Versions Default: affected
  • unaffected from 0:4.7.17-1.el9ap to * (excl.)
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.6
Versions Default: affected
  • unaffected from 1789673739 to * (excl.)
Vendor Red Hat
Product Red Hat Ansible Automation Platform 2.7
Versions Default: affected
  • unaffected from 1789580684 to * (excl.)

Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Credits

  • This issue was discovered by Laura Pardo (Red Hat).

References

Problem Types

  • Incomplete List of Disallowed Inputs CWE