SSRF and Credential Leakage in AWX Notification Backends
CVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.
CVE search metadata
CVE search record: CVE-2026-71366. Severity: high. CVSS: 7.7. KEV: no. Product: AWX. Brief: SSRF and Credential Leakage in AWX Notification Backends. Brief link: https://feed.craftedsignal.io/briefs/2026-08-awx-ssrf/
What's new
- 1. added coverage for AWX Aug 24, 20:03 via nvd
CVE-2026-71366 describes a critical server-side request forgery (SSRF) vulnerability impacting multiple notification backends within AWX, including Webhook, Mattermost, Rocket.Chat, and Grafana. The vulnerability exists because the application fails to validate user-supplied notification template URLs against private, loopback, or reserved IP ranges.
An attacker with notification administrator privileges can exploit this to force the AWX control node to perform HTTP requests against sensitive internal infrastructure or local services typically unreachable from the internet. The risk is compounded by secondary issues in the webhook backend, which follows HTTP redirects while improperly propagating configured Basic Authentication credentials to external, attacker-controlled hosts. Similarly, the Grafana backend exposes API keys in the Authorization header during these unauthorized requests. This issue enables both unauthorized internal network probing and the exfiltration of sensitive service credentials.
Impact
Successful exploitation allows an authenticated administrator to bypass network access controls to probe internal services and exfiltrate authentication tokens, potentially leading to privilege escalation or lateral movement within the network.
Recommendation
- Audit existing notification templates in AWX to identify URLs targeting internal network segments or loopback addresses.
- Implement strict egress filtering on the AWX control node to prevent unauthorized connections to internal resources.
- Rotate any credentials or API keys that have been configured in AWX notification templates, as these may have been exposed through the identified redirect and header leakage mechanisms.
- Apply vendor-supplied security patches for AWX to remediate the lack of URL validation.
Immediate actions
Audit notification templates for internal or loopback IP targets
Mitigations
Configure egress network policy to restrict AWX control node traffic to known/required notification endpoints
CVE-2026-71366