Red Hat Product Errata RHSA-2026:28376 - Security Advisory Issued: 2026-06-23 Updated: 2026-06-23 RHSA-2026:28376 - Security Advisory Overview Updated Packages Synopsis Critical: Red Hat Ansible Automation Platform 2.5 Product Security Update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.5 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-eda-controller: Websocket missing authorization allows credential theft via activation_id spoofing (CVE-2026-11807) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.5 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 9 aarch64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 x86_64 Red Hat Ansible Automation Platform 2.5 for RHEL 8 s390x Red Hat Ansible Automation Platform 2.5 for RHEL 8 ppc64le Red Hat Ansible Automation Platform 2.5 for RHEL 8 aarch64 Fixes BZ - 2487036 - CVE-2026-11807 eda-server: websocket missing authorization allows credential theft via activation_id spoofing CVEs CVE-2026-11807 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.5 for RHEL 9 SRPM automation-eda-controller-1.1.19-1.el9ap.src.rpm SHA-256: 6d118c128ef93d783139811aa49f47ee0500f8729c60e65ab83d41520083d69a x86_64 automation-eda-controller-1.1.19-1.el9ap.noarch.rpm SHA-256: 6dbc00907ac35f7cb33c28c5d54f9db5200bed56b16b972afed53f43a4a6743f automation-eda-controller-base-1.1.19-1.el9ap.noarch.rpm SHA-256: 80e379158ae4e2edd795da2f619b42afd19a8ad091177e9a2b38e8e83cb8337d automation-eda-controller-base-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 6bda9e4f28f82b07af7eb65f4c1ff0cb3837e034fa434ebf53551a3eb1a8b908 automation-eda-controller-event-stream-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 38e29c4053daa7bd2abc1f33cf09ad1235d736a905141f6ab030ce605f2b2a59 automation-eda-controller-worker-services-1.1.19-1.el9ap.noarch.rpm SHA-256: eff2addc1679e163d6922810a626a998ca4503ea8ecaf4fe756450bff7d68aea s390x automation-eda-controller-1.1.19-1.el9ap.noarch.rpm SHA-256: 6dbc00907ac35f7cb33c28c5d54f9db5200bed56b16b972afed53f43a4a6743f automation-eda-controller-base-1.1.19-1.el9ap.noarch.rpm SHA-256: 80e379158ae4e2edd795da2f619b42afd19a8ad091177e9a2b38e8e83cb8337d automation-eda-controller-base-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 6bda9e4f28f82b07af7eb65f4c1ff0cb3837e034fa434ebf53551a3eb1a8b908 automation-eda-controller-event-stream-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 38e29c4053daa7bd2abc1f33cf09ad1235d736a905141f6ab030ce605f2b2a59 automation-eda-controller-worker-services-1.1.19-1.el9ap.noarch.rpm SHA-256: eff2addc1679e163d6922810a626a998ca4503ea8ecaf4fe756450bff7d68aea ppc64le automation-eda-controller-1.1.19-1.el9ap.noarch.rpm SHA-256: 6dbc00907ac35f7cb33c28c5d54f9db5200bed56b16b972afed53f43a4a6743f automation-eda-controller-base-1.1.19-1.el9ap.noarch.rpm SHA-256: 80e379158ae4e2edd795da2f619b42afd19a8ad091177e9a2b38e8e83cb8337d automation-eda-controller-base-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 6bda9e4f28f82b07af7eb65f4c1ff0cb3837e034fa434ebf53551a3eb1a8b908 automation-eda-controller-event-stream-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 38e29c4053daa7bd2abc1f33cf09ad1235d736a905141f6ab030ce605f2b2a59 automation-eda-controller-worker-services-1.1.19-1.el9ap.noarch.rpm SHA-256: eff2addc1679e163d6922810a626a998ca4503ea8ecaf4fe756450bff7d68aea aarch64 automation-eda-controller-1.1.19-1.el9ap.noarch.rpm SHA-256: 6dbc00907ac35f7cb33c28c5d54f9db5200bed56b16b972afed53f43a4a6743f automation-eda-controller-base-1.1.19-1.el9ap.noarch.rpm SHA-256: 80e379158ae4e2edd795da2f619b42afd19a8ad091177e9a2b38e8e83cb8337d automation-eda-controller-base-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 6bda9e4f28f82b07af7eb65f4c1ff0cb3837e034fa434ebf53551a3eb1a8b908 automation-eda-controller-event-stream-services-1.1.19-1.el9ap.noarch.rpm SHA-256: 38e29c4053daa7bd2abc1f33cf09ad1235d736a905141f6ab030ce605f2b2a59 automation-eda-controller-worker-services-1.1.19-1.el9ap.noarch.rpm SHA-256: eff2addc1679e163d6922810a626a998ca4503ea8ecaf4fe756450bff7d68aea Red Hat Ansible Automation Platform 2.5 for RHEL 8 SRPM automation-eda-controller-1.1.19-1.el8ap.src.rpm SHA-256: bc998852c5736cd70218de09ac546cb7966c89507d40e7da1b35b5ff17a3bc7f x86_64 automation-eda-controller-1.1.19-1.el8ap.noarch.rpm SHA-256: 247cb4c4debe9f99f1ed3e92b47c7813ccff973f2d0d86a3c113c84cb3f02223 automation-eda-controller-base-1.1.19-1.el8ap.noarch.rpm SHA-256: 19b18ce6e58d76ee3f9b4ee8633d69b01019e397391cd3ec668517117e3add01 automation-eda-controller-base-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 87bf1bf30e2765e6d47124276c2190ba7d8c14d4ab6c09e0528ee15f5e69a2bb automation-eda-controller-event-stream-services-1.1.19-1.el8ap.noarch.rpm SHA-256: ca624508a7727def7a8860ebb60728dcbb94da4183d1dd0e69de59a9d40d06ba automation-eda-controller-worker-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 4c70b1645114143e70aa287b9658438faf3bc8a6e886b8fd86d2de9658931788 s390x automation-eda-controller-1.1.19-1.el8ap.noarch.rpm SHA-256: 247cb4c4debe9f99f1ed3e92b47c7813ccff973f2d0d86a3c113c84cb3f02223 automation-eda-controller-base-1.1.19-1.el8ap.noarch.rpm SHA-256: 19b18ce6e58d76ee3f9b4ee8633d69b01019e397391cd3ec668517117e3add01 automation-eda-controller-base-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 87bf1bf30e2765e6d47124276c2190ba7d8c14d4ab6c09e0528ee15f5e69a2bb automation-eda-controller-event-stream-services-1.1.19-1.el8ap.noarch.rpm SHA-256: ca624508a7727def7a8860ebb60728dcbb94da4183d1dd0e69de59a9d40d06ba automation-eda-controller-worker-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 4c70b1645114143e70aa287b9658438faf3bc8a6e886b8fd86d2de9658931788 ppc64le automation-eda-controller-1.1.19-1.el8ap.noarch.rpm SHA-256: 247cb4c4debe9f99f1ed3e92b47c7813ccff973f2d0d86a3c113c84cb3f02223 automation-eda-controller-base-1.1.19-1.el8ap.noarch.rpm SHA-256: 19b18ce6e58d76ee3f9b4ee8633d69b01019e397391cd3ec668517117e3add01 automation-eda-controller-base-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 87bf1bf30e2765e6d47124276c2190ba7d8c14d4ab6c09e0528ee15f5e69a2bb automation-eda-controller-event-stream-services-1.1.19-1.el8ap.noarch.rpm SHA-256: ca624508a7727def7a8860ebb60728dcbb94da4183d1dd0e69de59a9d40d06ba automation-eda-controller-worker-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 4c70b1645114143e70aa287b9658438faf3bc8a6e886b8fd86d2de9658931788 aarch64 automation-eda-controller-1.1.19-1.el8ap.noarch.rpm SHA-256: 247cb4c4debe9f99f1ed3e92b47c7813ccff973f2d0d86a3c113c84cb3f02223 automation-eda-controller-base-1.1.19-1.el8ap.noarch.rpm SHA-256: 19b18ce6e58d76ee3f9b4ee8633d69b01019e397391cd3ec668517117e3add01 automation-eda-controller-base-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 87bf1bf30e2765e6d47124276c2190ba7d8c14d4ab6c09e0528ee15f5e69a2bb automation-eda-controller-event-stream-services-1.1.19-1.el8ap.noarch.rpm SHA-256: ca624508a7727def7a8860ebb60728dcbb94da4183d1dd0e69de59a9d40d06ba automation-eda-controller-worker-services-1.1.19-1.el8ap.noarch.rpm SHA-256: 4c70b1645114143e70aa287b9658438faf3bc8a6e886b8fd86d2de9658931788 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical vulnerability (CVE-2026-11807, CVSS 9.6) in the automation-eda-controller component of Red Hat Ansible Automation Platform 2.5 allows credential theft via a missing authorization check in a websocket endpoint, which can be exploited through activation_id spoofing. The security advisory is rated Critical and affects Red Hat Ansible Automation Platform 2.5 running on RHEL 8 and 9 across multiple architectures. The fix is provided in the updated package version automation-eda-controller-1.1.19-1.