boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-71364

Red Hat Red Hat Ansible Automation Platform 2.5 for RHEL 8 — Awx: project archive extraction allows path traversal file writes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  H  H  H    7.2   .0172   76.7     —
AFFECTED
  Product                                             Versions     Fixed
  Red Hat Ansible Automation Platform 2.5 for RHEL 8  unspecified  0:4.6.32-1.el8ap
  Red Hat Ansible Automation Platform 2.5 for RHEL 9  unspecified  0:4.6.32-1.el9ap
  Red Hat Ansible Automation Platform 2.6 for RHEL 9  unspecified  0:4.7.16-1.el9ap
  Red Hat Ansible Automation Platform 2.6             unspecified  1787244009
  Red Hat Ansible Automation Platform 2.7             unspecified  1787220257
TIMELINE
  Aug 6   Reserved by redhat
  Aug 23  PATCH SHIPPED — CVE-2026-71364 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap.
  Aug 24  Published (CNA: redhat)
CWE-22 · CNA: redhat · CVSS v3.1 · 6 references · NVD status: Awaiting Analysis

Description

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without performing path normalization, boundary validation, or rejecting directory traversal sequences. A malicious archive containing members with path traversal components can write files to arbitrary locations on the execution node's filesystem outside the intended project directory. An attacker who controls the archive content, either through a compromised upstream source, a malicious archive URL, or a man-in-the-middle attack on a plain HTTP connection, can achieve arbitrary file writes as the user performing the extraction, potentially leading to remote code execution through mechanisms such as cron files, SSH authorized keys, or playbook content injection.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
August 6, 2026ReservedReserved by redhat
August 23, 2026PATCH SHIPPEDPATCH SHIPPED — CVE-2026-71364 (Red Hat Ansible Automation Platform 2.5 for RHEL 8). Fixed in Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:4.6.32-1.el8ap.
August 24, 2026PublishedPublished (CNA: redhat)

Affected

Affected products and packages — 5 rows
VendorProduct / PackageEcosystemVersion introducedFixed
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 8——0:4.6.32-1.el8ap
Red HatRed Hat Ansible Automation Platform 2.5 for RHEL 9——0:4.6.32-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 9——0:4.7.16-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.6——1787244009
Red HatRed Hat Ansible Automation Platform 2.7——1787220257

Weaknesses

CWE-22

References (6)

Related

Authoritative record: CVE-2026-71364 at cve.org

Vendors: red hat

Weaknesses: CWE-22

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-71364 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.