CVE-2025-9909 Details
Description
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.
A vulnerability exists in the Red Hat Ansible Automation Platform Gateway route creation component, specifically in versions 2.5 and 2.6. This flaw allows for credential theft by creating misleading routes with a double-slash prefix in the gateway_path. A malicious or socially engineered administrator could configure a honey-pot route to intercept and exfiltrate user credentials, potentially creating a backdoor for persistent access even after their permissions are revoked.
Users can upgrade to Red Hat Ansible Automation Platform 2.6 or 2.5, both of which include the necessary fix. Instructions for applying this update are available in the Red Hat Ansible Automation Platform 2.6 and 2.5 release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:21768 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:21775 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:23069 | [email protected] | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2025:23131 | [email protected] | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2025-9909 | [email protected] | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2392836 | [email protected] | Issue TrackingVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-647 | Use of Non-Canonical URL Paths for Authorization Decisions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| redhat ansible automation platform | < 2.6 |
CPE
Remediation
| |
| redhat ansible developer | 1.2 1.3 |
CPE
Remediation
| |
| redhat ansible inside | 1.3 1.4 |
CPE
Remediation
| |
| redhat enterprise linux | 8.0 9.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 25, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |