CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12564

criticalCVSS 9.6covered by 1 sourcefirst seen 2026-08-18
A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py reads the controller pod's Kubernetes service account token and sends it to an attacker-controlled URL when a HashiCorp Vault Secret Lookup credential with kubernetes_role authentication is tested. An authenticated attacker with credential-creation privileges can exfiltrate the service account token, gaining Kubernetes API access to the control plane namespaces with full pod CRUD and secret read permissions, including database credentials and the Django SECRET_KEY.

⚡ Watch CVE-2026-12564

Get an email if CVE-2026-12564 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-12564

CVE.org record

Embed the live status

CVE-2026-12564 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12564 status](https://www.csirts.com/badge/CVE-2026-12564)](https://www.csirts.com/cve/CVE-2026-12564)