CVE-2025-9909
Received
Received - Intake
Credential Theft via Route Manipulation in Red Hat Ansible Gateway
Publication date: 2026-02-27
Last updated on: 2026-03-25
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| redhat | ansible_developer | 1.2 |
| redhat | ansible_inside | 1.3 |
| redhat | ansible_automation_platform | to 2.6 (exc) |
| redhat | ansible_developer | 1.3 |
| redhat | ansible_inside | 1.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-647 | The product defines policy namespaces and makes authorization decisions based on the assumption that a URL is canonical. This can allow a non-canonical URL to bypass the authorization. |