Description

A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were exploited, an attacker‘s capabilities would only be limited by role based access controls (RBAC).

INFO

Published Date :

2026-01-08T13:44:04.764Z

Last Modified :

2026-02-26T15:04:54.734Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-14025 vulnerability.

Vendors Products
Redhat
  • Ansible Automation Platform

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact