# CVE-2025-9909

## Summary

- **CVE ID:** CVE-2025-9909
- **Severity:** MEDIUM
- **CVSS Score:** 6.7 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-647
- **Published:** Feb 27, 2026
- **Last Modified:** Mar 12, 2026

## Description

A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to intercept and exfiltrate user credentials, potentially maintaining persistent access or creating a backdoor even after their permissions are revoked.

## Affected Products

- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:3.1.1-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:25.12.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:25.12.2-1.1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:0.1.4-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:2.5.20251210-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:4.10.10-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:2.13.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:0.4.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:4.2.26-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:2.1.2-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:0.4.36-2.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:23.0.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:1.6.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:9.0.1-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:3.8.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:0.2.15-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:0.4.2-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:25.12.0-1.2.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 8 (0:4.15.0-1.el8ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:3.1.1-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:25.12.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:25.12.2-1.1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:0.1.4-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:2.5.20251210-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:4.10.10-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:2.13.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:0.4.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:4.2.26-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:2.1.2-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:0.4.36-2.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:23.0.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:1.6.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:9.0.1-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:3.8.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:0.2.15-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:0.4.2-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:25.12.0-1.2.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 for RHEL 9 (0:4.15.0-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.6 for RHEL 9 (0:2.6.20251119-1.el9ap)
- Red Hat — Red Hat Ansible Automation Platform 2.5 (sha256:93b5d66f1fa8a3241d999df47c8430c13fa11b751b5fc3d4a8fd2a39d282b3fd)
- Red Hat — Red Hat Ansible Automation Platform 2.6 (sha256:d6bd83a65b6a0ca9cead0652736c51dd1ab02fc8d9ee2a5c19e413a5239c0cb7)

## References

- [CNA](https://access.redhat.com/errata/RHSA-2025:21768)
- [CNA](https://access.redhat.com/errata/RHSA-2025:21775)
- [CNA](https://access.redhat.com/errata/RHSA-2025:23069)
- [CNA](https://access.redhat.com/errata/RHSA-2025:23131)
- [CNA](https://access.redhat.com/security/cve/CVE-2025-9909)
- [CNA](https://bugzilla.redhat.com/show_bug.cgi?id=2392836)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-12._