Unauthenticated Remote Code Injection Risk in Ansible Automation Platform's Event-Driven Ansible
CVE-2026-18141
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 31 July 2026
What is CVE-2026-18141?
A security flaw has been identified in the Ansible Automation Platform's Event-Driven Ansible (EDA) component. This vulnerability enables unauthenticated remote attackers to bypass mutual Transport Layer Security (mTLS) authentication for event streams. By manipulating the event stream URL and forging the HTTP Subject header, attackers can inject arbitrary events into EDA. Additionally, error messages reveal the expected certificate subject, further assisting in facilitating the attack. This outcome poses a risk of unauthorized execution of automated workflows.
Affected Version(s)
Red Hat Ansible Automation Platform 2.6 1785780020
Red Hat Ansible Automation Platform 2.6 for RHEL 9 0:1.2.11-1.el9ap
Red Hat Ansible Automation Platform 2.7 1785435970