CVE-2026-18141
Red Hat · Ansible Automation Platform 2
A flaw in the aap-gateway component of Red Hat Ansible Automation Platform 2 allows unauthenticated attackers to bypass mTLS authentication for event streams.
Executive summary
An authentication bypass vulnerability in Red Hat Ansible Automation Platform 2 allows unauthenticated remote attackers to forge credentials and manipulate event streams.
Vulnerability
This is an improper certificate validation issue (CWE-295) in the aap-gateway. An unauthenticated attacker can bypass mutual TLS authentication by manipulating the event stream URL and forging the HTTP Subject header, which is further simplified by the system disclosing expected subject names in error messages.
Business impact
With a CVSS score of 8.2, this vulnerability represents a high risk to the integrity of automated workflows. Exploitation could allow attackers to inject malicious events into the automation platform, leading to unauthorized configuration changes or the execution of arbitrary tasks across the managed environment.
Remediation
Immediate Action: Apply security updates provided by Red Hat immediately as they become available on the official security advisory page.
Proactive Monitoring: Review logs for anomalous event stream activity or unauthorized attempts to access the aap-gateway.
Compensating Controls: Restrict network access to the aap-gateway component to only trusted sources and ensure that mTLS configurations are audited for signs of tampering.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
The ability for an unauthenticated attacker to bypass critical security controls makes this a high-priority remediation task. Organizations should immediately review their Ansible Automation Platform deployments and apply the vendor-recommended patches to prevent unauthorized control over automation event streams.