CVE-2025-9907
CVE-2025-9907 is a medium-severity vulnerability in Redhat Ansible Automation Platform with a CVSS 3.x base score of 6.7. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-200.
Key facts
- Severity: Medium (CVSS 3.x base score 6.7)
- EPSS exploit prediction: 0% (6th percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2025-208132
- Weakness: CWE-200
- Affected product: Redhat Ansible Automation Platform
- Published:
- Last modified:
Description
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
Frequently asked questions
- What is CVE-2025-9907?
- A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of internal infrastructure details, accidental disclosure of user or system credentials, privilege escalation if high-value tokens are exposed, and persistent sensitive data exposure to all users with read access on the event stream.
- How severe is CVE-2025-9907?
- CVE-2025-9907 has a CVSS 3.x base score of 6.7, rated medium severity. It is exploitable over local access with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2025-9907 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (6th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2025-9907?
- CVE-2025-9907 primarily affects Redhat Ansible Automation Platform. In total, 5 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2025-9907?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2025-9907 have an EU (EUVD) identifier?
- Yes. CVE-2025-9907 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2025-208132.
- When was CVE-2025-9907 published?
- CVE-2025-9907 was published on 2026-02-27 and last updated on 2026-06-17.
References
- https://access.redhat.com/errata/RHSA-2025:19201
- https://access.redhat.com/errata/RHSA-2025:19221
- https://access.redhat.com/errata/RHSA-2025:23069
- https://access.redhat.com/errata/RHSA-2025:23131
- https://access.redhat.com/security/cve/CVE-2025-9907
- https://bugzilla.redhat.com/show_bug.cgi?id=2392834
Affected products (5)
- cpe:2.3:a:redhat:ansible_automation_platform:*:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_developer:1.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_developer:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_inside:1.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ansible_inside:1.4:*:*:*:*:*:*:*
More vulnerabilities in Redhat Ansible Automation Platform
- CVE-2021-4112 — High (CVSS 8.8): A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw…
- CVE-2026-46625 — High (CVSS 7.5): JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal…
- CVE-2023-50782 — High (CVSS 7.5): A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured…
- CVE-2023-44487 — High (CVSS 7.5): The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset…
- CVE-2021-20228 — High (CVSS 7.5): A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by…
- CVE-2023-4237 — High (CVSS 7.3): A flaw was found in the Ansible Automation Platform. When creating a new keypair, the ec2_key module prints out the…
All CVEs affecting Redhat Ansible Automation Platform →
Other CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities
- CVE-2026-92960 — Critical (CVSS 10.0): vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing…
- CVE-2026-92947 — Critical (CVSS 10.0): vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by…
- CVE-2026-70478 — Critical (CVSS 10.0): Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST…
- CVE-2026-27604 — Critical (CVSS 10.0): FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version…
- CVE-2026-40965 — Critical (CVSS 10.0): Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a…
- CVE-2026-42826 — Critical (CVSS 10.0): Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose…
Browse all CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) vulnerabilities →