Unauthenticated Remote Code Injection Risk in Ansible Automation Platform's Event-Driven Ansible
CVE-2026-18141

8.2HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
31 July 2026

What is CVE-2026-18141?

A security flaw has been identified in the Ansible Automation Platform's Event-Driven Ansible (EDA) component. This vulnerability enables unauthenticated remote attackers to bypass mutual Transport Layer Security (mTLS) authentication for event streams. By manipulating the event stream URL and forging the HTTP Subject header, attackers can inject arbitrary events into EDA. Additionally, error messages reveal the expected certificate subject, further assisting in facilitating the attack. This outcome poses a risk of unauthorized execution of automated workflows.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.