CVE-2026-52902

Summary

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx –conf.format yaml import". This is a client-side vulnerability requiring user interaction.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 80:4.6.32-1.el8ap < *unaffected
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 90:4.6.32-1.el9ap < *unaffected
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 90:4.7.16-1.el9ap < *unaffected
Red HatRed Hat Ansible Automation Platform 2.7 for RHEL 100:4.8.6-1.el10ap < *unaffected
Red HatRed Hat Ansible Automation Platform 2.7 for RHEL 90:4.8.6-1.el9ap < *unaffected

Weaknesses

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Workarounds

The following practices would help for avoiding exposure to this flaw:

  1. Prioritize the default JSON import format instead of YAML.
  2. Avoid importing YAML files from untrusted sources.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References