Medium severity6.7NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026
CVE-2025-9909
CVE-2025-9909
Description
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10cpe:/a:redhat:ansible_automation_platform:2.5::el8+ 5 more
- cpe:/a:redhat:ansible_automation_platform:2.5::el8range: sha256:93b5d66f1fa8a3241d999df47c8430c13fa11b751b5fc3d4a8fd2a39d282b3fd
- cpe:/a:redhat:ansible_automation_platform:2.6::el9range: sha256:d6bd83a65b6a0ca9cead0652736c51dd1ab02fc8d9ee2a5c19e413a5239c0cb7
- cpe:/a:redhat:ansible_automation_platform_developer:2.6::el9range: 0:2.6.20251119-1.el9ap
- cpe:/a:redhat:ansible_automation_platform_inside:2.5::el9range: 0:4.15.0-1.el9ap
- cpe:2.3:a:redhat:ansible_automation_platform:*:*:*:*:*:*:*:*range: <2.6
- (no CPE)
cpe:2.3:a:redhat:ansible_developer:1.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:ansible_developer:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_developer:1.3:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_inside:1.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:ansible_inside:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_inside:1.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2025:21768nvdVendor Advisory
- access.redhat.com/errata/RHSA-2025:21775nvdVendor Advisory
- access.redhat.com/errata/RHSA-2025:23069nvdVendor Advisory
- access.redhat.com/errata/RHSA-2025:23131nvdVendor Advisory
- access.redhat.com/security/cve/CVE-2025-9909nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.