VYPR

AAP Controller

by Red Hat

CVEs (1)

  • CVE-2026-12564CriAug 18, 2026
    risk 0.62cvss 9.6epss

    A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault…