boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-52902

Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Awxkit: path traversal via yaml !include directive
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   N   R  U  H  N  N    4.7   .0016    4.2     —
AFFECTED
  Product                                              Versions     Fixed
  Red Hat Ansible Automation Platform 2.5 for RHEL 8   unspecified  0:4.6.32-1.el8ap
  Red Hat Ansible Automation Platform 2.5 for RHEL 9   unspecified  0:4.6.32-1.el9ap
  Red Hat Ansible Automation Platform 2.6 for RHEL 9   unspecified  0:4.7.16-1.el9ap
  Red Hat Ansible Automation Platform 2.7 for RHEL 10  unspecified  0:4.8.6-1.el10ap
  Red Hat Ansible Automation Platform 2.7 for RHEL 9   unspecified  0:4.8.6-1.el9ap
  Red Hat Ansible Automation Platform 2                unspecified  —
  Red Hat Ansible Automation Platform 2                unspecified  —
  Red Hat Ansible Automation Platform 2                unspecified  —
  Red Hat Ansible Automation Platform 2                unspecified  —
  Red Hat Ansible Automation Platform 2                unspecified  —
  + 5 more
TIMELINE
  Jun 9   Reserved by redhat
  Jun 9   Published (CNA: redhat)
  Aug 23  PATCH SHIPPED — CVE-2026-52902 (Red Hat Ansible Automation Platform 2.7 for RHEL 10). Fixed in Red Hat Ansible Automation Platform 2.7 for RHEL 10 0:4.8.6-1.el10ap.
CWE-22 · CNA: redhat · CVSS v3.1 · 5 references · NVD status: Awaiting Analysis

Description

A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize file paths, allowing an attacker to craft a malicious YAML file that reads arbitrary YAML-formatted files from the local filesystem when a user imports it using "awx --conf.format yaml import". This is a client-side vulnerability requiring user interaction.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
June 9, 2026ReservedReserved by redhat
June 9, 2026PublishedPublished (CNA: redhat)
August 23, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-52902 (Red Hat Ansible Automation Platform 2.7 for RHEL 10). Fixed in Red Hat Ansible Automation Platform 2.7 for RHEL 10 0:4.8.6-1.el10ap.

Affected

Affected products and packages — 15 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8——0:4.6.32-1.el8ap
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9——0:4.6.32-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9——0:4.7.16-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.7 for RHEL 10——0:4.8.6-1.el10ap
Red HatRed Hat Ansible Automation Platform 2.7 for RHEL 9——0:4.8.6-1.el9ap
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———
Red HatRed Hat Ansible Automation Platform 2———

Weaknesses

CWE-22

References (5)

Related

Authoritative record: CVE-2026-52902 at cve.org

Vendors: red hat

Weaknesses: CWE-22

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-52902 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.