VYPR

AWX

by Red Hat

CVEs (2)

  • CVE-2026-76648HigSep 23, 2026
    risk 0.55cvss 8.5epss 0.00

    CopyAPIView (awx/awx/api/generics.py:873) sets permission_classes = (IsAuthenticated,), so DRF's get_object() performs no object-level RBAC. The get() handler (lines 988–991) explicitly guards with request.user.can_access(obj._class_, 'read', obj) — but post() (lines…

  • CVE-2026-71365HigAug 18, 2026
    risk 0.50cvss 7.7epss 0.00

    A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks, AWX extracts the status callback URL (pull_request.statuses_url) from the incoming webhook payload without validating the target…