Red Hat patches RCE and path traversal flaws in Ansible Automation Platform 2.7
An Important-rated update addresses a GeoDjango remote-code-execution flaw and an automation-controller-cli path traversal issue.
Red Hat has issued an Important-rated security update for Ansible Automation Platform 2.7, fixing a remote-code-execution vulnerability in Django and a path traversal flaw in the platform’s command-line tooling. The vendor’s RHSA-2026:59137 advisory was issued August 24 and covers Ansible Automation Platform 2.7 deployments on RHEL 9 and RHEL 10, along with affected Ansible Developer 1.4 and Ansible Inside 1.5 packages.
What the update fixes
The more consequential issue is CVE-2026-15307, which Red Hat describes as remote code execution through GeoDjango spatial lookups. The advisory updates the Django packages bundled with the affected Ansible Automation Platform channels to version 5.2.17 builds. Red Hat lists both the Python and Python 3.12 Django packages among the corrected components.
The same update fixes CVE-2026-52902 in automation-controller-cli. Red Hat says the flaw allows path traversal through the YAML !include directive. Corrected CLI packages are listed as version 4.8.6 builds for the affected RHEL 9 and RHEL 10 channels.
The advisory also rolls forward a broader set of Ansible developer-tool packages, including ansible-creator, ansible-navigator, ansible-lint, Molecule, and the Ansible development environment. Those package updates form part of the security and bug-fix release, but the advisory identifies the Django and controller CLI issues as its security fixes.
Who should act
The affected-product list includes Ansible Automation Platform 2.7 for RHEL 9 and RHEL 10 on x86_64 and aarch64. It also names corresponding Ansible Developer 1.4 builds and Ansible Inside 1.5 on RHEL 9.
Administrators should use the Red Hat advisory to identify the package set for their channel and apply the update through the supported Ansible Automation Platform upgrade process. Because Red Hat rates the combined update Important and one corrected flaw can lead to remote code execution, this is an operational patch rather than a routine tool refresh.
sources
comments · 0