RHSA-2026:28440CriticalCVSS 9.6
Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.7 Container Release Update
🔗 CVE IDs covered (1)
📋 Description
CVE-2026-11807 — eda-server: websocket missing authorization allows credential theft via activation_id spoofing
🎯 Affected products9
- Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:0fc501f79b57632a0afa165ae50384964d6d8f0c22b69f09b4d5a687bd15f402_arm64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9-operator@sha256:6208fb3fc2eaaa3fec1f2716bcd2d3db8b3f60cbb2f5b0a0f781026bf2465b4e_amd64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:5534ffce8512326cfaf5f951995a5d48454f3565dde5ea6368839f245c6d3346_arm64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform-27/eda-controller-rhel9@sha256:ae3eae342e9f09fad3bbf16170189d97c8930d63b08d3026651f62620fea558c_amd64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:518645014efff9714835adf0b614cce22236d7a50675d8f24e699118d2f9b649_arm64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform-27/eda-controller-ui-rhel9@sha256:ce0bfcfe8bd8fbec9bd4ef127f97b0035e540eb7ead15ba572ed9a8ce2894af8_amd64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:1d7336a746b35764d705c3a68f0f0e2a8426eaa1e75f504b193900fcdcdb80ec_amd64 as a component of Red Hat Ansible Automation Platform 2.7
- registry.redhat.io/ansible-automation-platform/platform-operator-bundle@sha256:56c701ab118c1b91ff55af524e69d2c8970784c185e13950fc13b3ff495f05d2_amd64 as a component of Red Hat Ansible Automation Platform 2.7
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7#Upgrade Workaround: The following practices would help for reducing or avoiding the exposure to this flaw: 1) Restrict network access to the EDA websocket endpoint. 2) Review and limit user accounts with any level of Ansible Automation Platform authentication until the fix is applied.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2026:28440
- externalhttps://access.redhat.com/security/cve/CVE-2026-11807
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.7/whats_new-async_updates
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_28440.json