{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18141/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-18141"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ansible Automation Platform"],"_cs_severities":["high"],"_cs_tags":["cve-2026-18141","authentication-bypass","automation"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eA high-severity vulnerability, tracked as CVE-2026-18141, affects the aap-gateway component of Red Hat Ansible Automation Platform's Event-Driven Ansible (EDA). The flaw enables an unauthenticated remote attacker to bypass mutual Transport Layer Security (mTLS) authentication when communicating with event streams. By manipulating the target event stream URL and forging the HTTP Subject header, an attacker can successfully authenticate as a trusted source.\u003c/p\u003e\n\u003cp\u003eThe exploitation process is further aided by an information disclosure issue within the gateway, which returns the expected certificate subject in error messages during failed connection attempts. This allows attackers to identify the required Subject string for header forgery. Successful exploitation allows for the injection of arbitrary events into the EDA system, which can result in the execution of unauthorized automated workflows. This poses a significant risk to organizations using EDA for automated infrastructure or application management.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to inject arbitrary events into the Event-Driven Ansible system. This can lead to the unauthorized triggering of automated workflows, which may involve system configuration changes, service restarts, or other administrative actions configured within the EDA platform. The impact includes potential loss of integrity for automated processes and unauthorized manipulation of managed infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch the Ansible Automation Platform environment to the version provided by Red Hat that addresses CVE-2026-18141.\u003c/li\u003e\n\u003cli\u003eReview webserver logs for the aap-gateway component to identify anomalous requests, specifically looking for high frequencies of 401 or 403 errors that may indicate an attacker probing for the required certificate subject.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the EDA gateway endpoint to trusted source IP addresses to limit the exposure of the management interface to the public internet.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-31T17:39:42Z","date_published":"2026-07-31T17:39:42Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ansible-gateway-mtls-bypass/","summary":"An unauthenticated remote attacker can bypass mTLS authentication in the aap-gateway component of Event-Driven Ansible to inject arbitrary events and trigger automated workflows.","title":"CVE-2026-18141: mTLS Bypass in Ansible Automation Platform","url":"https://feed.craftedsignal.io/briefs/2026-07-ansible-gateway-mtls-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18141","version":"https://jsonfeed.org/version/1.1"}