{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-71364/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-71366"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWX"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","ssrf","credential-leakage","path-traversal","arbitrary-file-write","remote-code-execution","cve-2026-71364"],"_cs_type":"advisory","_cs_vendors":["Ansible"],"content_html":"\u003cp\u003eCVE-2026-71366 describes a critical server-side request forgery (SSRF) vulnerability impacting multiple notification backends within AWX, including Webhook, Mattermost, Rocket.Chat, and Grafana. The vulnerability exists because the application fails to validate user-supplied notification template URLs against private, loopback, or reserved IP ranges.\u003c/p\u003e\n\u003cp\u003eAn attacker with notification administrator privileges can exploit this to force the AWX control node to perform HTTP requests against sensitive internal infrastructure or local services typically unreachable from the internet. The risk is compounded by secondary issues in the webhook backend, which follows HTTP redirects while improperly propagating configured Basic Authentication credentials to external, attacker-controlled hosts. Similarly, the Grafana backend exposes API keys in the Authorization header during these unauthorized requests. This issue enables both unauthorized internal network probing and the exfiltration of sensitive service credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated administrator to bypass network access controls to probe internal services and exfiltrate authentication tokens, potentially leading to privilege escalation or lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit existing notification templates in AWX to identify URLs targeting internal network segments or loopback addresses.\u003c/li\u003e\n\u003cli\u003eImplement strict egress filtering on the AWX control node to prevent unauthorized connections to internal resources.\u003c/li\u003e\n\u003cli\u003eRotate any credentials or API keys that have been configured in AWX notification templates, as these may have been exposed through the identified redirect and header leakage mechanisms.\u003c/li\u003e\n\u003cli\u003eApply vendor-supplied security patches for AWX to remediate the lack of URL validation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T20:03:15Z","date_published":"2026-08-24T18:03:56Z","id":"https://feed.craftedsignal.io/briefs/2026-08-awx-ssrf/","summary":"CVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.","title":"SSRF and Credential Leakage in AWX Notification Backends","url":"https://feed.craftedsignal.io/briefs/2026-08-awx-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-71364","version":"https://jsonfeed.org/version/1.1"}