Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18141— Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header

CVSS 8.2 · High EPSS 0.25% · P17

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 4

VendorProductVersion RangeStatus
Red HatRed Hat Ansible Automation Platform 2anyunaffected
anyaffected
anyaffected
anyaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-18141

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypass mutual Transport Layer Security (mTLS) authentication for event streams. This is achieved by manipulating the event stream URL and forging the HTTP Subject header. The system also inadvertently discloses the expected certificate subject in error messages, which simplifies the attack. This vulnerability allows an attacker to inject arbitrary events into EDA, potentially triggering automated workflows.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
Red Hat Ansible Automation Platform 加密问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Red Hat Ansible Automation Platform是美国Red Hat公司的一款信息化产品。 Red Hat Ansible Automation Platform 2版本存在加密问题漏洞,该漏洞源于aap-gateway组件绕过mTLS认证问题,攻击者可通过操纵事件流URL和伪造HTTP Subject头,利用错误消息中泄露的证书主题信息,向EDA注入任意事件,可能触发自动化工作流。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Ansible Automation Platform 2-cpe:/a:redhat:ansible_automation_platform:2
Red HatRed Hat Ansible Automation Platform 2-cpe:/a:redhat:ansible_automation_platform:2
Red HatRed Hat Ansible Automation Platform 2-cpe:/a:redhat:ansible_automation_platform:2
Red HatRed Hat Ansible Automation Platform 2-cpe:/a:redhat:ansible_automation_platform:2

II. Public POCs for CVE-2026-18141

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18141

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18141 (2)

Same Patch Batch · Red Hat · 2026-07-31 · 14 CVEs total

CVE-2026-100798.5 HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injecti
CVE-2026-157227.5 HIGH389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_
CVE-2026-117707.5 HIGH389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check
CVE-2026-182156.8 MEDIUMKeycloak-services: keycloak-services: microsoft external access-token exchange bypasses co
CVE-2026-182146.8 MEDIUMKeycloak-services: keycloak-services: google external access-token exchange bypasses hoste
CVE-2026-182086.5 MEDIUMKeycloak-services: keycloak-services: inactive out-of-audience token introspection leaks s
CVE-2026-182036.5 MEDIUMKeycloak-services: keycloak-services: group policy extendchildren matches sibling group pa
CVE-2026-161054.9 MEDIUMKeycloak-services: keycloak-services: missing per-role authorization on rolecontainerresou
CVE-2026-182184.2 MEDIUMKeycloak-services: keycloak-services: client not-before revocation ignored when realm not-
CVE-2026-182114.2 MEDIUMKeycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefi
CVE-2026-182063.7 LOWKeycloak-services: keycloak-services: client policy source-host wildcard domain matching b
CVE-2026-182173.4 LOWKeycloak-services: keycloak-services: saml http-redirect binding response preserves query
CVE-2026-182093.4 LOWKeycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-18141

No comments yet


Leave a comment