216.73.216.133

CVE-2025-14025

· Published 08/01/2026 14:15 · Modified 08/01/2026 23:15

Labels: CVE-2025-14025 2026-01-08CVE-2025-14025CWE-279[email protected]

Essential information

Published
08/01/2026 14:15
Modified
08/01/2026 23:15
Author
Creator
CVSS
8.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS metrics

Description

A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were exploited, an attacker‘s capabilities would only be limited by role based access controls (RBAC).

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
redhat / ansible automation platform cpe:2.3:a:redhat:ansible_automation_platform:*:*:*:*:*:*:*:*

References