Vulnerability Description
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2026:50336
- https://access.redhat.com/errata/RHSA-2026:50340
- https://access.redhat.com/errata/RHSA-2026:50479
- https://access.redhat.com/security/cve/CVE-2026-18141
- https://bugzilla.redhat.com/show_bug.cgi?id=2508155
FAQ
What is CVE-2026-18141?
CVE-2026-18141 is a vulnerability with a CVSS score of 8.2 (HIGH). A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentic...
How severe is CVE-2026-18141?
CVE-2026-18141 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18141?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.