CVE-2026-11807Patch

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible-rulebook endpoint does not verify user permissions when processing Worker messages. Any authenticated user can send a forged message with an arbitrary activation_id to receive plaintext credentials associated with that activation, including OAuth tokens, vault passwords, and SSH keys.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-06-26); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-06-23: 1Mentions · 2026-06-24: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 3Mentions · 2026-07-15: 1Patch / Workaround · 2026-06-23: 1Patch / Workaround · 2026-06-24: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-23: 1Technical Details · 2026-06-24: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 206-2306-2406-2506-2607-15
Signal classification3 categories
Patch
342.9%
Disclosure
342.9%
General
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-231
Patch1
2026-06-241
Patch1
2026-06-251
Disclosure1
2026-06-263
Disclosure2Patch1
2026-07-151
General1
Full discourse7 posts
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    A missing authorization flaw in Event-Driven Ansible (CVE-2026-11807, CVSS 9.6) leaks credentials like OAuth tokens, vault passwords, and SSH keys. #Ansible #RedHat #CyberSecurity #CVE #PatchNow https://securityonline.info/event-driven-ansible-flaw https://t.co/yB1r2qscYg

    Post summary

    The post announces a high‑severity missing authorization flaw in Event‑Driven Ansible causing credential leakage, but does not include PoC, exploit code, or active exploitation claims.

    02041735
    12.8K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-11807 — CVSS 9.6/10 ██████████ A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/R1I1wML9as

    Post summary

    The tweet announces CVE‑2026‑11807, a critical missing‑authorization flaw in Ansible’s EDA websocket API, and urges users to apply the available patch.

    10000115
    59 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-11807: Event-Driven Ansible Websocket Missing Authorization Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04pDbBD0

    Post summary

    The post appears to be an informational article about the CVE, offering general guidance without providing technical specifics or evidence of exploitation.

    0000042
    32 followersView on X
  • Merge News@mergenewsapp
    Patch

    Event-Driven Ansible has a critical flaw (CVE-2026-11807) leaking credentials via its websocket API. Patch now! #security #vulnerability #ansible #eventdriven

    Post summary

    CVE-2026-11807 causes credential leakage in Event-Driven Ansible’s websocket API, and a patch has been released.

    0000027
    21 followersView on X
  • David C.@davidcorto
    Disclosure

    🚨 Alerta DevOps: Fuga de credenciales en Ansible Automation Platform (CVE-2026-11807). Un fallo crítico que expone los secretos de tu infraestructura. https://devops-daily.com/posts/ansible-automation-platform-credential-leak-cve-2026-11807 #DevSecOps #DevOps #Ansible #Security

    Post summary

    The tweet announces a credential‑leak vulnerability (CVE‑2026‑11807) in Ansible Automation Platform, but gives no technical details, PoC, or mitigation information.

    0000050
    368 followersView on X
  • DevOps Daily@thedevopsdaily
    Disclosure

    📝 Your Automation Platform Is a Credential Honeypot: Ansible CVE-2026-11807 A missing authorization check in Event-Driven Ansible lets any logged-in user pull plaintext vault p https://devops-daily.com/posts/ansible-automation-platform-credential-leak-cve-2026-11807 #DevOps #Security

    Post summary

    The post highlights a missing authorization check in Ansible’s Event‑Driven component (CVE‑2026‑11807) that can expose plaintext vault contents to any authenticated user, with no PoC or exploit code mentioned.

    0000059
    104 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CRITICAL - Missing authorization in EDA websocket API leaks activation secrets (CVE-2026-11807) A missing authorization flaw in Event-Driven Ansible (EDA) websocket API affects the /api/eda/ws/ansible-rulebook endpoint in the EDA controller when processing Worker messages. The root cause is improper access control/authorization checks (IDOR-style) allowing activation_id references without validating the requesting user’s permissions. An attacker only needs to be an authenticated user, then can send a forged websocket Worker message with an arbitrary activation_id to retrieve secrets tied to that activation. Impact is severe credential disclosure in plaintext, including OAuth tokens, vault passwords, and SSH keys, enabling lateral movement, privilege escalation, and full environment compromise. 👉 Affected: ansible-automation-platform-25/eda-controller-rhel8, ansible-automation-platform-26/eda-controller-rhel9, automation-eda-controller (all affected versions) | Upgrade to Vendor fix version (not specified) or No fix yet - treat as suspicious

    Post summary

    A critical IDOR flaw in the EDA websocket API exposes sensitive credentials; vendor fixes are pending and only a conservative workaround is advised.

    0000082
    226 followersView on X

Explore more