CVE-2025-9907
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows an attacker to access sensitive client credentials and internal system details through a specific field when the event stream is in test mode. If an attacker has read access to the event stream, they could potentially see this sensitive information, leading to risks like privilege escalation or ongoing exposure of critical data.
Technical Description
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 27, 2026
about 1 month ago
Last Modified
Feb 27, 2026
about 1 month ago