Impact
AAP Gateway allows a remote attacker to bypass mutual TLS authentication by injecting a spoofed Subject HTTP header that matches a legitimate client certificate distinguished name. Because the non-mTLS route to EDA event streams does not remove this header as intended, the attacker can impersonate an authenticated client and inject arbitrary events into protected EDA event streams. The vulnerability thus grants authentication bypass and enables unauthorized event injection, potentially compromising the integrity and confidentiality of event data and any downstream processes that consume those streams. The weakness corresponds to CWE‑290, Unauthorized Function Use via Authentication Bypass.
Affected Systems
Red Hat Ansible Automation Platform versions including the RHEL 8, 9, and 10 editions of the platform as well as the developer and inside variants. The specific impacted packages are the Ansible Automation Platform 2.5 for RHEL 8 and 9, 2.6 (and 2.6 for RHEL 9), and 2.7 editions. All related CPE strings listed in the CVE data correspond to these products.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, while the EPSS score of less than 1 % reflects a very low yet non‑zero probability of exploitation at the time of assessment. The vulnerability is not listed in the CISA KEV catalog, which suggests no confirmed widespread exploitation yet. An attacker can exploit the flaw by sending a crafted HTTP request to the non‑mTLS event‑stream route (/eda‑event‑streams/) and including a forged Subject header that matches a valid client certificate DN. Because the proxy fails to strip requires network reach to the non‑mTLS route, making it actionable for external adversaries targeting exposed AAP Gateway instances.
OpenCVE Enrichment