Executive brief
A security vulnerability has been identified in the Event-Driven Ansible (EDA) server, a tool used to automate IT tasks based on real-time events. The system fails to properly verify the identity of incoming requests and inadvertently reveals the specific security credentials it expects to see in error messages. This allows an unauthorized person to bypass security checks and inject fake events into the system, potentially triggering unintended automated actions across the corporate infrastructure.
Technical details
A vulnerability exists in the Event-Driven Ansible (EDA) server's ExternalEventStreamViewSet due to permissive access controls (AllowAny) and a lack of authentication classes. The component relies on the Subject HTTP header for mTLS authentication but fails to verify if the header originated from a trusted proxy. Furthermore, the server leaks the expected certificate Distinguished Name (DN) in 403 Forbidden error responses. An unauthenticated remote attacker can exploit this by capturing the expected DN from an error message and then spoofing the Subject header to bypass authentication. This allows the injection of arbitrary events into mTLS-protected streams, which can trigger downstream automation playbooks.
Affected products
- Red Hat Ansible Automation Platform 2 2.0
- Red Hat eda-server
Timeline
- 2026-06-16: other: Initial report in Red Hat Bugzilla
- 2026-07-27: disclosed: CVE published to NVD