Product
high
advisory
Authorization Bypass in AWX CopyAPIView
1 TTP 1 CVECVE-2026-76648 is an authorization bypass vulnerability in the AWX CopyAPIView component where improper object-level RBAC checks allow attackers to perform copy operations on Job Templates without necessary read permissions.
AWX
1t
1c
high
advisory
SSRF and Credential Leakage in AWX Notification Backends
3 TTPs 1 CVECVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.
AWX
web-vulnerability
ssrf
credential-leakage
path-traversal
arbitrary-file-write
remote-code-execution
cve-2026-71364
3t
1c