Authentication Bypass Vulnerability in AAP Gateway Envoy Proxy by Red Hat
CVE-2026-12382
Key Information:
What is CVE-2026-12382?
A flaw in the configuration of the AAP Gateway Envoy proxy has been identified, where the non-mTLS route to EDA event streams fails to eliminate the Subject HTTP header from client requests. Although the source code specifies requestHeadersToRemove for this header, it is not processed correctly. This oversight allows an unauthenticated remote attacker to inject a spoofed Subject header that can match a legitimate client certificate Distinguished Name (DN), thus bypassing mTLS authentication. Consequently, this enables the attacker to inject arbitrary events into the protected EDA event streams, posing a severe security risk.
Affected Version(s)
Red Hat Ansible Automation Platform 2.5 for RHEL 8 0:2.5.20260715-1.el8ap
Red Hat Ansible Automation Platform 2.5 for RHEL 9 0:2.5.20260715-1.el9ap
Red Hat Ansible Automation Platform 2.6 1777311120