CVE-2026-12382
HIGHAap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
Title source: cnaDescription
A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.
References (6)
Core 6
Core References
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2026-12382
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:13508
https://access.redhat.com/errata/RHSA-2026:13508
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:13545
https://access.redhat.com/errata/RHSA-2026:13545
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:42078
https://access.redhat.com/errata/RHSA-2026:42078
Vendor Advisory vendor-advisory
x_refsource_redhat
RHSA-2026:42142
https://access.redhat.com/errata/RHSA-2026:42142
Issue Tracking, X_Refsource_Redhat issue-tracking
x_refsource_redhat
RHBZ#2489126
https://bugzilla.redhat.com/show_bug.cgi?id=2489126
Scores
CVSS v3
8.2
EPSS
0.0037
EPSS Percentile
29.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-290
Status
published
Products (6)
Red Hat/Red Hat Ansible Automation Platform 2
Red Hat/Red Hat Ansible Automation Platform 2.5 for RHEL 8
0:2.5.20260715-1.el8ap
Red Hat/Red Hat Ansible Automation Platform 2.5 for RHEL 9
0:2.5.20260715-1.el9ap
Red Hat/Red Hat Ansible Automation Platform 2.6
1777311120
Red Hat/Red Hat Ansible Automation Platform 2.6 for RHEL 9
0:2.6.20260422-1.el9ap
Red Hat/Red Hat Ansible Automation Platform 2.7
1783919486
Published
Jul 15, 2026
Tracked Since
Jul 15, 2026