Description

A flaw was found in the AAP gateway. The user auto-link strategy, introduced in AAP 2.6, automatically links an external Identity Provider (IDP) identity to an existing AAP user account based on email matching without verifying email ownership. This allows a remote attacker to potentially hijack a victim's account or gain unauthorized access to other accounts, including administrative accounts, by manipulating the IDP-provided email.

INFO

Published Date :

2026-05-04T13:47:07.260Z

Last Modified :

2026-05-05T03:56:19.819Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-6266 vulnerability.

Vendors Products
Redhat
  • Ansible Automation Platform
  • Ansible Automation Platform Developer
  • Ansible Automation Platform Inside

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact