CVE-2026-18141
Last modified
CVE-2026-18141 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.6 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2.7 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-18141?
How severe is CVE-2026-18141?
How do I fix CVE-2026-18141?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18125An out-of-bounds read in the Agent of Ivanti Endpoint Manage…7.5
- CVE-2026-18127External control of a filename in the Core of Ivanti Endpoin…7.7
- CVE-2026-18129Cleartext transmission of sensitive information in the Core …8.1
- CVE-2026-1813A vulnerability was found in bolo-blog bolo-solo up to 2.6.4…9.8
- CVE-2026-1814Rapid7 Nexpose versions 6.4.50 and later are vulnerable to a…6.8
- CVE-2026-18140Uncontrolled recursion in the unknown-key skip path of the a…8.7
- CVE-2026-1815Insufficient session expiration vulnerability in Turkiye Ele…5.7
- CVE-2026-18157A flaw was found in yggdrasil-worker-package-manager. A loca…7.8
- CVE-2026-1816Improper restriction of excessive authentication attempts vu…6.3
- CVE-2026-18171Docker Sandboxes (sbx) applies the read-only intent of a run…5.7
- CVE-2026-18174@fastify/forwarded resolves client addresses from the X-Forw…5.3
- CVE-2026-18186A stored format string vulnerability was found in the FTP Ba…8.1
Are you affected by CVE-2026-18141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
