CVE-2026-18141: Improper Certificate Validation in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
AI Analysis
Technical Summary
The vulnerability exists in the aap-gateway component of Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA). An attacker can bypass mutual TLS authentication by manipulating the event stream URL and forging the HTTP Subject header. Additionally, error messages disclose the expected certificate subject, facilitating targeted attacks. This allows injection of arbitrary events into EDA event streams, which may trigger automated workflows without authentication. The flaw is due to improper certificate validation and authentication bypass in the aap-gateway configuration.
Potential Impact
An unauthenticated remote attacker can bypass mutual TLS authentication and inject arbitrary events into the EDA event streams. This can lead to unauthorized triggering of automated workflows, potentially causing unintended actions within the automation platform. Confidentiality impact is low, integrity impact is high, and availability is not affected according to the CVSS score. The vulnerability could allow attackers to assume identity and bypass protection mechanisms in the affected component.
Mitigation Recommendations
Red Hat has not explicitly stated that a patch is available for this vulnerability in the provided advisory content. The recommended mitigation is to restrict network access to the EDA event stream endpoints at the firewall or load balancer level, ensuring only trusted sources can reach these ports. Additionally, monitoring EDA event logs for unexpected events from unverified sources is advised. Check Red Hat's official advisory and errata for updates on patches or fixes and apply them when available.
CVE-2026-18141: Improper Certificate Validation in Red Hat Red Hat Ansible Automation Platform 2.6 for RHEL 9
Description
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
CVSS v3.1
Score 8.2high
Affected software
Red Hat
Red Hat Ansible Automation Platform 2.6 for RHEL 9
Red Hat
Red Hat Ansible Automation Platform 2.6
Red Hat
Red Hat Ansible Automation Platform 2.7
Red Hat
Red Hat Ansible Automation Platform 2
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the aap-gateway component of Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA). An attacker can bypass mutual TLS authentication by manipulating the event stream URL and forging the HTTP Subject header. Additionally, error messages disclose the expected certificate subject, facilitating targeted attacks. This allows injection of arbitrary events into EDA event streams, which may trigger automated workflows without authentication. The flaw is due to improper certificate validation and authentication bypass in the aap-gateway configuration.
Potential Impact
An unauthenticated remote attacker can bypass mutual TLS authentication and inject arbitrary events into the EDA event streams. This can lead to unauthorized triggering of automated workflows, potentially causing unintended actions within the automation platform. Confidentiality impact is low, integrity impact is high, and availability is not affected according to the CVSS score. The vulnerability could allow attackers to assume identity and bypass protection mechanisms in the affected component.
Mitigation Recommendations
Red Hat has not explicitly stated that a patch is available for this vulnerability in the provided advisory content. The recommended mitigation is to restrict network access to the EDA event stream endpoints at the firewall or load balancer level, ensuring only trusted sources can reach these ports. Additionally, monitoring EDA event logs for unexpected events from unverified sources is advised. Check Red Hat's official advisory and errata for updates on patches or fixes and apply them when available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-07-28T18:47:42.043Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-18141","vendor":"Red Hat"}]
Threat ID: 6a6cf74bbf32cb7a342947f8
Added to database: 07/31/2026, 19:28:11 UTC
Last enriched: 08/08/2026, 14:05:34 UTC
Last updated: 09/15/2026, 22:01:32 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.