CVE-2025-9907 Details
Description
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
A vulnerability exists in the Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA) Event Stream API. When an event stream is in test mode, the API endpoint exposes sensitive client credentials and internal infrastructure headers through the test_headers field. This flaw can lead to the unintentional disclosure of user or system credentials, leakage of internal infrastructure details, and, if high-value tokens are exposed, privilege escalation. Additionally, the exposed sensitive data remains accessible to all users with read access on the event stream until it is explicitly overwritten or deleted.
Users can upgrade to Red Hat Ansible Automation Platform 2.6 for RHEL 9 or 2.5 for RHEL 9 or 8, all of which include the necessary fix. Instructions for applying this update are available in the Red Hat Ansible Automation Platform documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:19201 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:19221 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:23069 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:23131 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2025-9907 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2392834 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat ansible automation platform | < 2.6 |
CPE
Remediation
| |
| redhat ansible developer | 1.2 1.3 |
CPE
Remediation
| |
| redhat ansible inside | 1.3 1.4 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 26, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |