Bug 2537465 (CVE-2026-94416) - CVE-2026-94416 aap-gateway: aap-gateway: authorization bypass via workload identity token forgery
Summary: CVE-2026-94416 aap-gateway: aap-gateway: authorization bypass via workload id...
Keywords:
Status: NEW
Alias: CVE-2026-94416
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-21 15:52 UTC by OSIDB Bzimport
Modified: 2026-09-30 07:14 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-21 15:52:26 UTC
Reported internally by Red Hat engineering (Robin Bobbitt) via PSIRTSUPT-24014 / AAP-66516.

Root cause: the gateway API (POST /api/gateway/v1/service_keys/) lets an AAP administrator mint a valid HS256 signing secret for the Controller service identity. Nothing constrains service-key creation to the installer provisioning path, so an admin-issued key is indistinguishable from a legitimately provisioned one. Possession of it lets the admin forge a service-auth JWT that impersonates the Controller service and then call POST /api/gateway/v1/workload_identity_tokens/ (X-ANSIBLE-SERVICE-AUTH: <forged JWT>) with arbitrary workload claims, obtaining a gateway-signed RS256 Workload Identity Token for any real or contrived Controller workload. That WIT is accepted by any downstream resource server (e.g. HashiCorp Vault) trusting the gateway OIDC public key, returning the AAP credentials configured for that workload.

Preconditions: attacker is an AAP administrator (PR:H); FEATURE_OIDC_WORKLOAD_IDENTITY_ENABLED=true; a downstream resource server trusts the gateway OIDC key and grants access by WIT claims.

Version applicability: the workload-identity endpoint and feature flag exist in AAP 2.7, where the full chain is exploitable. In AAP 2.5 and 2.6 the service-key-creation precondition exists but the WIT endpoint does not, so there is no privilege escalation there; however a forged service-auth token yields an attribution/audit-trail bypass (actions can be attributed to the service the key was minted for, or to another user). A service key created in 2.5/2.6 persists across upgrade and remains valid for WIT forgery once the flag is enabled in 2.7. AAP 2.4 has no gateway and is not affected.

Upstream fix (public): https://github.com/ansible/jewel/pull/235 (gateway service). Related collection update: https://github.com/ansible/ansible.platform/pull/254 (does not itself fix the vulnerability).


Note You need to log in before you can comment on or make changes to this bug.