VDB

CVE-2026-18141

CVE-2026-18141 PUBLISHED CVSS 8.2 HIGH

Reported by redhat · Published July 31, 2026

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.

Risk Scores

CVSS 3.1
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Affected Products

VendorProductVersions
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 90:1.2.11-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.61785780020
Red HatRed Hat Ansible Automation Platform 2.71785435970
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2.61785780020
Red HatRed Hat Ansible Automation Platform 2
Red HatRed Hat Ansible Automation Platform 2.6 for RHEL 90:1.2.11-1.el9ap
Red HatRed Hat Ansible Automation Platform 2.71785435970

Timeline

  • Jul 31, 2026 CVE Published
  • Aug 1, 2026 Coalition ESS Score
  • Aug 2, 2026 EPSS Score
  • Aug 4, 2026 CVE Updated
  • Aug 5, 2026 Distribution Patch
  • Aug 5, 2026 Distribution Patch
  • Aug 5, 2026 Distribution Patch
  • Aug 5, 2026 Security Advisory
  • Aug 5, 2026 Security Advisory
  • Aug 5, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›