CVE 8.5 HIGH

Ansible-automation-platform/aap-gateway: aap-gateway: read-only personal access token (pat) bypasses write restrictions_CVE-2025-14025

8.5 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were exploited, an attackerβ€˜s capabilities would only be limited by role based access controls (RBAC).

AI Analysis

Read-only OAuth2 API Tokens vulnerability allowing write operations on backend services

Basic Information

ID CVE-2025-14025
Source redhat
Published Jan 8, 2026 at 13:44

Affected Product

Vendor Red Hat
Product Red Hat Ansible Automation Platform 2

CWE Classification

AI Assessment

AI Score 8.5 / 10
AI Severity High
Vendor Red Hat
Product Ansible Automation Platform
Version 2

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.