CVE-2026-12383
Red Hat · Red Hat Ansible Automation Platform 2
The Event-Driven Ansible server is vulnerable to event injection due to insufficient verification of data authenticity and reliance on spoofable HTTP headers.
Executive summary
A flaw in the Red Hat Ansible Automation Platform 2 Event-Driven Ansible server allows unauthenticated attackers to inject malicious events into protected streams.
Vulnerability
The vulnerability (CWE-345) involves permissive access controls and an over-reliance on a spoofable Subject HTTP header during mTLS authentication. This flaw permits an attacker to inject arbitrary events into event streams that are intended to be protected by mTLS, thereby triggering unintended downstream automation.
Business impact
With a CVSS score of 7.5, this vulnerability presents a significant risk to the integrity of automated infrastructure workflows. Successful exploitation allows an attacker to manipulate automation outcomes, which could lead to unauthorized configuration changes, system disruption, or the execution of arbitrary tasks within the managed environment.
Remediation
Immediate Action: Review the official Red Hat security advisory for the specific patch version and apply the required updates to the Event-Driven Ansible server.
Proactive Monitoring: Inspect automation logs for anomalous event triggers or events originating from unexpected or non-authenticated sources.
Compensating Controls: Restrict network access to the EDA server to trusted management subnets and enforce strict mTLS validation policies at the network edge if possible.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a serious risk to automated systems and requires prompt attention. Organizations should monitor the Red Hat security portal for the latest patch information and apply the necessary updates to secure their Ansible automation pipelines against event injection.