Red Hat Product Errata RHSA-2026:28377 - Security Advisory Issued: 2026-06-23 Updated: 2026-06-23 RHSA-2026:28377 - Security Advisory Overview Updated Packages Synopsis Critical: Red Hat Ansible Automation Platform 2.6 Product Security Update Type/Severity Security Advisory: Critical Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update is now available for Red Hat Ansible Automation Platform 2.6 Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Ansible Automation Platform provides an enterprise framework for building, deploying and managing IT automation at scale. IT Managers can provide top-down guidelines on how automation is applied to individual teams, while automation developers retain the freedom to write tasks that leverage existing knowledge without the overhead. Ansible Automation Platform makes it possible for users across an organization to share, vet, and manage automation content by means of a simple, powerful, and agentless language. Security Fix(es): automation-eda-controller: Websocket missing authorization allows credential theft via activation_id spoofing (CVE-2026-11807) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, refer to Ansible Automation Platform documentation. Affected Products Red Hat Ansible Automation Platform 2.6 for RHEL 9 x86_64 Red Hat Ansible Automation Platform 2.6 for RHEL 9 s390x Red Hat Ansible Automation Platform 2.6 for RHEL 9 ppc64le Red Hat Ansible Automation Platform 2.6 for RHEL 9 aarch64 Fixes BZ - 2487036 - CVE-2026-11807 eda-server: websocket missing authorization allows credential theft via activation_id spoofing CVEs CVE-2026-11807 References https://access.redhat.com/security/updates/classification/#critical Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Ansible Automation Platform 2.6 for RHEL 9 SRPM automation-eda-controller-1.2.9-2.el9ap.src.rpm SHA-256: 8614bb0354b7c3d2a8b0f348aa65c280c4f8a829163b8ce36beb13de99058adf x86_64 automation-eda-controller-1.2.9-2.el9ap.noarch.rpm SHA-256: aa8e84807c31510b8ab124d6b9f3380533892a505a86ed24681bf6e74dd50024 automation-eda-controller-base-1.2.9-2.el9ap.noarch.rpm SHA-256: 3b570c57bbfb73ec8cf2e28b52df56f7bf2df426032db1d58c28c408715efd02 automation-eda-controller-base-services-1.2.9-2.el9ap.noarch.rpm SHA-256: ada5cdecf1f76e5e462c58c4906346a3eef7b0b199438bd642ee9780d78c5744 automation-eda-controller-event-stream-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 6a2de569cba8856cd1f93cbbc8c6fdd759a9b33cc5f304e18ed833977f1fab93 automation-eda-controller-worker-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 090d2ba551c7faf4f8121ce52fb51270d691eea08c2a332e536fc6c315eba7c2 s390x automation-eda-controller-1.2.9-2.el9ap.noarch.rpm SHA-256: aa8e84807c31510b8ab124d6b9f3380533892a505a86ed24681bf6e74dd50024 automation-eda-controller-base-1.2.9-2.el9ap.noarch.rpm SHA-256: 3b570c57bbfb73ec8cf2e28b52df56f7bf2df426032db1d58c28c408715efd02 automation-eda-controller-base-services-1.2.9-2.el9ap.noarch.rpm SHA-256: ada5cdecf1f76e5e462c58c4906346a3eef7b0b199438bd642ee9780d78c5744 automation-eda-controller-event-stream-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 6a2de569cba8856cd1f93cbbc8c6fdd759a9b33cc5f304e18ed833977f1fab93 automation-eda-controller-worker-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 090d2ba551c7faf4f8121ce52fb51270d691eea08c2a332e536fc6c315eba7c2 ppc64le automation-eda-controller-1.2.9-2.el9ap.noarch.rpm SHA-256: aa8e84807c31510b8ab124d6b9f3380533892a505a86ed24681bf6e74dd50024 automation-eda-controller-base-1.2.9-2.el9ap.noarch.rpm SHA-256: 3b570c57bbfb73ec8cf2e28b52df56f7bf2df426032db1d58c28c408715efd02 automation-eda-controller-base-services-1.2.9-2.el9ap.noarch.rpm SHA-256: ada5cdecf1f76e5e462c58c4906346a3eef7b0b199438bd642ee9780d78c5744 automation-eda-controller-event-stream-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 6a2de569cba8856cd1f93cbbc8c6fdd759a9b33cc5f304e18ed833977f1fab93 automation-eda-controller-worker-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 090d2ba551c7faf4f8121ce52fb51270d691eea08c2a332e536fc6c315eba7c2 aarch64 automation-eda-controller-1.2.9-2.el9ap.noarch.rpm SHA-256: aa8e84807c31510b8ab124d6b9f3380533892a505a86ed24681bf6e74dd50024 automation-eda-controller-base-1.2.9-2.el9ap.noarch.rpm SHA-256: 3b570c57bbfb73ec8cf2e28b52df56f7bf2df426032db1d58c28c408715efd02 automation-eda-controller-base-services-1.2.9-2.el9ap.noarch.rpm SHA-256: ada5cdecf1f76e5e462c58c4906346a3eef7b0b199438bd642ee9780d78c5744 automation-eda-controller-event-stream-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 6a2de569cba8856cd1f93cbbc8c6fdd759a9b33cc5f304e18ed833977f1fab93 automation-eda-controller-worker-services-1.2.9-2.el9ap.noarch.rpm SHA-256: 090d2ba551c7faf4f8121ce52fb51270d691eea08c2a332e536fc6c315eba7c2 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical authorization flaw (CVE-2026-11807, CVSS 9.6) in the automation-eda-controller websocket allows an attacker to steal credentials by spoofing an activation_id. The vulnerability affects Red Hat Ansible Automation Platform 2.6, and the fix is provided in the updated package automation-eda-controller-1.2.9-2.el9ap. Administrators should apply the update immediately following the official Ansible Automation Platform documentation.