Junglewise Threat Intelligence

CVE-2026-18141: Red Hat Ansible Automation Platform mTLS bypass in aap-gateway

CVE-2026-18141 · Severity: high · CVSS 8.2 · Published 2026-07-31

Executive brief

A security flaw exists in the gateway component of Red Hat's Event-Driven Ansible (EDA), which is used to automate IT tasks based on real-time events. An unauthorized attacker can bypass security checks to send fake events into the system. This could allow an attacker to trigger automated workflows, potentially leading to unauthorized changes or actions across the managed IT environment.

Technical details

A vulnerability in aap-gateway, a component of Event-Driven Ansible (EDA) within the Ansible Automation Platform, allows for an mTLS authentication bypass. The flaw stems from improper validation where an attacker can manipulate the event stream URL and forge the HTTP Subject header to impersonate a trusted client. Furthermore, the system inadvertently leaks the expected certificate subject in error messages, providing the attacker with the necessary information to craft a successful forgery. This allows an unauthenticated remote attacker to inject arbitrary events, which may trigger automated playbooks or workflows. The vulnerability is tracked as CWE-295 (Improper Certificate Validation).

Affected products

  • Red Hat Ansible Automation Platform 2 2.5, 2.6, 2.7

Timeline

  • 2026-07-28: other: Reported to Red Hat Bugzilla
  • 2026-07-31: disclosed: CVE published

References