CRITICAL 9.1 NVD
CVE-2026-75884
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing inj
A flaw was found in AWX. The container group pod_spec_override field uses an incomplete blocklist that only restricts automountServiceAccountToken, allowing injection of initContainers, serviceAccountName overrides, and projected service account token volumes. An AAP platform administrator can exploit this to escalate privileges to OpenShift namespace-level access and exfiltrate namespace secrets.
References
- https://access.redhat.com/errata/RHSA-2026:71113
- https://access.redhat.com/errata/RHSA-2026:71115
- https://access.redhat.com/security/cve/CVE-2026-75884
- https://bugzilla.redhat.com/show_bug.cgi?id=2517893
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-23 via NVD.
Risk Timeline
CVE Disclosed2026-09-23 · -1 days ago
Remediation Resources
Official Advisory
access.redhat.com/errata/RHSA-2026:71113Official Advisory
access.redhat.com/errata/RHSA-2026:71115Analysis & PoC
bugzilla.redhat.com/show_bug.cgi?id=2517893
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.