CVE-2026-12382

HIGH

Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing

Title source: cna
STIX 2.1

Description

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

References (6)

Core 6
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-12382
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:13508
https://access.redhat.com/errata/RHSA-2026:13508
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:13545
https://access.redhat.com/errata/RHSA-2026:13545
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:42078
https://access.redhat.com/errata/RHSA-2026:42078
Vendor Advisory vendor-advisory x_refsource_redhat
RHSA-2026:42142
https://access.redhat.com/errata/RHSA-2026:42142
Issue Tracking, X_Refsource_Redhat issue-tracking x_refsource_redhat
RHBZ#2489126
https://bugzilla.redhat.com/show_bug.cgi?id=2489126

Scores

CVSS v3 8.2
EPSS 0.0037
EPSS Percentile 29.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (6)
Red Hat/Red Hat Ansible Automation Platform 2
Red Hat/Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:2.5.20260715-1.el8ap
Red Hat/Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:2.5.20260715-1.el9ap
Red Hat/Red Hat Ansible Automation Platform 2.6 1777311120
Red Hat/Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:2.6.20260422-1.el9ap
Red Hat/Red Hat Ansible Automation Platform 2.7 1783919486
Published Jul 15, 2026
Tracked Since Jul 15, 2026