CVE-2026-18141
Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header
Record summary
CVE-2026-18141 has a selected CVSS score of 8.2 (high).
Description
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 31, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Red Hat Ansible Automation Platform 2Browse Red Hat / Red Hat Ansible Automation Platform 2ansible-automation-platform-25/gateway-rhel8Default status: unaffected | CVE List | Version data not supplied | |
Red Hat Ansible Automation Platform 2.6Browse Red Hat / Red Hat Ansible Automation Platform 2.6ansible-automation-platform-26/gateway-rhel9Default status: affected | CVE List | 1785780020 to < * | unaffected |
Red Hat Ansible Automation Platform 2.6 for RHEL 9Browse Red Hat / Red Hat Ansible Automation Platform 2.6 for RHEL 9automation-eda-controllerDefault status: affected | CVE List | 0:1.2.11-1.el9ap to < * | unaffected |
Red Hat Ansible Automation Platform 2.7Browse Red Hat / Red Hat Ansible Automation Platform 2.7ansible-automation-platform-27/gateway-rhel9Default status: affected | CVE List | 1785435970 to < * | unaffected |