What is CVE-2026-16544?
This vulnerability in AWX involves incomplete RBAC authorization checks in the websocket event consumer, where only certain event groups are verified, potentially allowing unauthorized access to sensitive events like inventory_update_events, project_update_events, and system_job. Users should upgrade to the latest AWX version to mitigate this issue.
Azərbaycanca: AWX platformasında aşkar edilmiş bu boşluq websocket hadisə istehlakçısında RBAC yoxlamalarının yalnız müəyyən qruplar üçün aparılmasına səbəb olur, bu da icazəsiz istifadəçilərin inventory_update_events, project_update_events və system_job kimi həssas hadisələrə giriş əldə etməsinə yol aça bilər. Təsirə məruz qalmamaq üçün AWX-in son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What sensitive events can be accessed through CVE-2026-16544 in AWX?
This vulnerability may allow unauthorized access to sensitive events such as inventory_update_events, project_update_events, and system_job.
How to mitigate CVE-2026-16544?
Users should upgrade to the latest AWX version to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.