CVE-2025-9909 - CVE House
Back to Database
Status published Medium CVE-2025-9909

Aap-gateway: improper path validation in gateway allows credential exfiltration

Vulnerability Description

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-9909

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Elijah DeLee (Red Hat).

Affected Vendor

Affected Software

Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9, Red Hat Ansible Automation Platform 2.5, Red Hat Ansible Automation Platform 2.6
Vulnerable Versions:
0:3.1.1-1.el8ap, 0:25.12.0-1.el8ap, 0:25.12.2-1.1.el8ap, 0:0.1.4-1.el8ap, 0:2.5.20251210-1.el8ap, 0:4.10.10-1.el8ap, 0:2.13.0-1.el8ap, 0:0.4.0-1.el8ap, 0:4.2.26-1.el8ap, 0:2.1.2-1.el8ap, 0:0.4.36-2.el8ap, 0:23.0.0-1.el8ap, 0:1.6.0-1.el8ap, 0:9.0.1-1.el8ap, 0:3.8.0-1.el8ap, 0:0.2.15-1.el8ap, 0:0.4.2-1.el8ap, 0:25.12.0-1.2.el8ap, 0:4.15.0-1.el8ap, 0:3.1.1-1.el9ap, 0:25.12.0-1.el9ap, 0:25.12.2-1.1.el9ap, 0:0.1.4-1.el9ap, 0:2.5.20251210-1.el9ap, 0:4.10.10-1.el9ap, 0:2.13.0-1.el9ap, 0:0.4.0-1.el9ap, 0:4.2.26-1.el9ap, 0:2.1.2-1.el9ap, 0:0.4.36-2.el9ap, 0:23.0.0-1.el9ap, 0:1.6.0-1.el9ap, 0:9.0.1-1.el9ap, 0:3.8.0-1.el9ap, 0:0.2.15-1.el9ap, 0:0.4.2-1.el9ap, 0:25.12.0-1.2.el9ap, 0:4.15.0-1.el9ap, 0:2.6.20251119-1.el9ap, sha256:93b5d66f1fa8a3241d999df47c8430c13fa11b751b5fc3d4a8fd2a39d282b3fd, sha256:d6bd83a65b6a0ca9cead0652736c51dd1ab02fc8d9ee2a5c19e413a5239c0cb7

Timeline

Official Publish: February 27th, 2026
Last Modified: February 27th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.