TLS Certificate Validation Flaw in OCAPI Modules of Ansible Collection by Red Hat
CVE-2026-87872
6.8MEDIUM
What is CVE-2026-87872?
A significant vulnerability exists in the OCAPI modules of the community.general Ansible collection, where TLS certificate validation is disabled for all requests. This flaw allows attackers positioned within the network path to exploit unsecured connections. Without the ability to re-enable TLS validation, sensitive HTTP Basic Authentication credentials are sent to HTTPS endpoints without proper security measures. Consequently, attackers can intercept sessions, capture credentials, and manipulate responses, posing serious security threats to users and their configurations.
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Jeong Woochang for reporting this issue.