AAP 2.7-8 closes critical GitPython and Vault paths across controller and hub
The September patch maps Git command-injection and Kubernetes token-exfiltration fixes to specific Ansible Automation Platform components and operator builds.
Red Hat’s Ansible Automation Platform 2.7-8 update is not a single-library refresh. The September 14 release notes place the most consequential fixes in Automation Controller and Automation Hub, while a separate Vault credential fix lands in Controller.
What changed
The update ships Automation Controller 4.8.8, Automation Hub 4.12.6, Event-Driven Ansible 1.3.10 and Receptor 1.6.8. For OpenShift installations, Red Hat lists new namespace- and cluster-scoped AAP Operator builds under the 2.7.0 channel.
Controller and Hub both receive a broad GitPython repair set covering unsafe clone options, command injection, malicious Git templates, environment-variable exposure and arbitrary file operations. Controller moves to GitPython 3.1.59; Hub receives 3.1.57 or later. The release notes attach the remote-code and command-execution fixes to the controller-rhel9 and hub-rhel9 images rather than every AAP service.
Controller also fixes CVE-2026-12564 in the HashiCorp Vault credential plugin. Red Hat says the flaw could expose a Kubernetes service-account token through server-side request forgery. The corrected path obtains short-lived, audience-scoped credentials through Kubernetes’ TokenRequest API.
Who needs to act
Teams running Automation Controller or private Automation Hub should treat 2.7-8 as the upgrade target when project synchronization or other workflows consume Git URLs or options that are not fully controlled by administrators. Clusters using the Vault credential plugin have a second reason to prioritize Controller 4.8.8, because that component contains the token-exfiltration fix.
The operator update also creates runtime NetworkPolicy resources for Controller, Hub, Event-Driven Ansible, Lightspeed, the platform gateway, the resource operator and the metrics service. That is a useful containment change, but it does not replace the patched application images.
Upgrade check
Operators should verify that the resulting deployment reports Controller 4.8.8 and Hub 4.12.6, and that the installed AAP Operator build matches one of the two builds Red Hat lists for 2.7-8. Environments that use the containerized installer should move to bundle or online installer 2.7-8.
After the update, test source-control project synchronization and any Controller credentials backed by HashiCorp Vault. For OpenShift deployments, inspect the generated NetworkPolicy objects before assuming existing cross-namespace integrations will continue to reach AAP pods. The release contains many lower-severity dependency fixes, but the practical upgrade decision rests on whether Controller, Hub and the Vault credential path are present.
sources
comments · 0