CVE-2026-12564
Red Hat Red Hat Ansible Automation Platform 2
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and th...
- CVSS
- 9.6
- EPSS
- 0.28% 19.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19