Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-87872— Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure

Quick assessment

Affected
Red Hat Red Hat Ceph Storage 5
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 community.general Ansible 集合的 OCAPI 模块(ocapi_command、ocapi_info)中发现了一个缺陷。共享的 OCAPI 请求辅助函数在所有请求中禁用了 TLS 证书验证,且这些模块没有提供参数来重新启用该验证功能,同时它们会向 HTTPS 端点发送 HTTP 基本身份验证(Basic-Auth)凭据。位于 Ansible 控制器与 OCAPI 管理的存储/机箱设备之间网络路径上的攻击者可以出示任意证书,截获会话、捕获凭据,并篡改响应内容。

CVSS 6.8 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-87872

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
证书验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Ceph Storage 5 - cpe:/a:redhat:ceph_storage:5
Red Hat Red Hat Ceph Storage 9 - cpe:/a:redhat:ceph_storage:9
Red Hat Red Hat OpenStack Platform 17.1 - cpe:/a:redhat:openstack:17.1
Red Hat Red Hat OpenStack Platform 18.0 - cpe:/a:redhat:openstack:18.0

II. Public POCs for CVE-2026-87872

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-87872

登录查看更多情报信息。

Other References for CVE-2026-87872 (2)

Same Patch Batch · Red Hat · 2026-09-09 · 8 CVEs total

CVE-2026-87766 8.8 HIGH Bubblewrap: bubblewrap: symlink traversal via /oldroot allows writing files outside sandbo
CVE-2026-18147 8.1 HIGH Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execut
CVE-2026-87874 8.1 HIGH Community.general: community.general: memcached cache plugin deserializes untrusted pickle
CVE-2026-87853 7.5 HIGH Sssd: sssd: idp authentication prefix comparison allows cross-user impersonation
CVE-2026-19729 4.9 MEDIUM Keycloak-services: keycloak-services: incomplete fix for arbitrary filesystem path probing
CVE-2026-87875 4.3 MEDIUM Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-l
CVE-2026-87876 3.0 LOW Cups: openprinting cups: remaining case-insensitive username matching in scheduler side pa

IV. Related Vulnerabilities

V. Comments for CVE-2026-87872

No comments yet


Leave a comment