Bug 2418785 (CVE-2025-14025) - CVE-2025-14025 ansible-automation-platform/aap-gateway: aap-gateway: Read-only Personal Access Token (PAT) bypasses write restrictions
Summary: CVE-2025-14025 ansible-automation-platform/aap-gateway: aap-gateway: Read-onl...
Keywords:
Status: NEW
Alias: CVE-2025-14025
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-04 12:33 UTC by OSIDB Bzimport
Modified: 2026-01-08 14:09 UTC (History)
22 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:0360 0 None None None 2026-01-08 14:09:30 UTC
Red Hat Product Errata RHSA-2026:0361 0 None None None 2026-01-08 14:09:43 UTC

Description OSIDB Bzimport 2025-12-04 12:33:03 UTC
See bug report https://issues.redhat.com/browse/AAP-59025
Create a Personal Access Token (PAT) on Gateway, the user account in this was an admin account. Configure the token's scope to be read-only. Use the token to attempt a write operation on the Controller component. The write operation proceeds despite the token being read-only. Attempt to create a new team on Gateway and the operation correctly fails as Gateway uses the read-only scope. While the user account was an admin account, the token's read-only scope should have been acknowledged. This does not feel like a true escalation of privileges vulnerability since the user account was an admin.

Comment 3 errata-xmlrpc 2026-01-08 14:09:28 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9

Via RHSA-2026:0360 https://access.redhat.com/errata/RHSA-2026:0360

Comment 4 errata-xmlrpc 2026-01-08 14:09:40 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 8
  Red Hat Ansible Automation Platform 2.5 for RHEL 9

Via RHSA-2026:0361 https://access.redhat.com/errata/RHSA-2026:0361


Note You need to log in before you can comment on or make changes to this bug.