Vendor
Authorization Bypass in AWX CopyAPIView
1 TTP 1 CVECVE-2026-76648 is an authorization bypass vulnerability in the AWX CopyAPIView component where improper object-level RBAC checks allow attackers to perform copy operations on Job Templates without necessary read permissions.
Remote Code Execution in Ansible community.general Memcached Plugin
1 TTP 1 CVEAn insecure deserialization vulnerability in the community.general Ansible collection's memcached cache plugin allows unauthenticated attackers to achieve remote code execution via pickle payload injection.
SSRF and Credential Leakage in AWX Notification Backends
3 TTPs 1 CVECVE-2026-71366 allows authenticated AWX notification administrators to perform SSRF and exfiltrate credentials by leveraging insufficient validation of notification template targets.
Ansible jailexec Plugin Jail Escape via Symlink Following
1 TTPThe ansible_jailexec connection plugin performs file operations with host-side root privileges while following symlinks, allowing an attacker to escape a FreeBSD jail and gain root access on the host.