CVE-2026-94416: Aap-gateway: aap-gateway: authorization bypass via workload identity token forgery

Published Sep 24, 2026
·
Updated

An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authenticated administrator to create a new service key for the Controller service cluster. Because service-key creation is not restricted to the installer-provisioned provisioning path, an administrator-issued key is cryptographically indistinguishable from a legitimate one and can be used to forge a service-authentication token that impersonates the Controller service. Combined with the gateway OIDC workload-identity endpoint (enabled via FEATUREOIDCWORKLOADIDENTITYENABLED), the attacker can drive the gateway to sign Workload Identity Tokens (WITs) for arbitrary Controller workloads. A downstream resource server such as HashiCorp Vault that trusts the gateway OIDC key will accept the forged WIT and return the AAP credentials bound to that workload, disclosing secrets beyond the attacker's authorization boundary.

Affected Software

1 affected component
Red Hat Ansible Automation Platform gateway

Event History

Sep 24, 2026
CVE Published
via MITRE·12:25 PM
Data Sourced
via MITRE·12:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated AAP gateway administrator is required. The attacker must be able to create a service key for the Controller service cluster and use it to impersonate the Controller service.

2

What configuration makes this issue exploitable?

The gateway OIDC workload-identity endpoint must be enabled through FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED. A downstream resource server must also trust the gateway OIDC signing key and expose credentials for a Controller workload.

3

What is the likely impact on downstream systems?

An attacker can obtain Workload Identity Tokens for arbitrary Controller workloads. A trusting resource server, such as HashiCorp Vault, may accept those forged tokens and disclose the AAP credentials associated with the targeted workload.

4

How can exposure be reduced if a fix cannot be applied immediately?

Disable the gateway OIDC workload-identity endpoint by disabling FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED. Also review which downstream resource servers trust the gateway OIDC key and limit or remove that trust where possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203