Skip to content
Red HatCVE-2026-71364

Red Hat AWX: path traversal

High7.2CVE-2026-71364 · Published Aug 24, 2026 · updated Aug 28, 2026

A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip and tar archive members by joining the project directory path with the member filename without performing path normalization, boundary validation, or rejecting directory traversal sequences. A malicious archive containing members with path traversal components can write files to arbitrary locations on the execution node's filesystem outside the intended project directory. An attacker who controls the archive content, either through a compromised upstream source, a malicious archive URL, or a man-in-the-middle attack on a plain HTTP connection, can achieve arbitrary file writes as the user performing the extraction, potentially leading to remote code execution through mechanisms such as cron files, SSH authorized keys, or playbook content injection.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in CRI-O's container-creation environment-variable handling
Medium6.0Aug 24
Red Hat GIMP: denial of service
Medium6.1Aug 24
Red Hat file-pcx plugin: integer overflow
High7.0Aug 24
Red Hat Enterprise Linux 10: improper authorization
High7.1Aug 24
Red Hat multiple AWX: server-side request forgery
High7.7Aug 24
Red Hat WebKitGTK: use after free
High8.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.