CVE-2026-12382

HIGH CVSS 3.1: 8.2 EPSS 0.37%
Updated Aug 12, 2026
Red Hat
Parameter Value
CVSS 8.2 (HIGH)
Type CWE-290
Vendor Red Hat
Public PoC No

A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from client requests, despite the source code defining requestHeadersToRemove for this header. An unauthenticated remote attacker can inject a spoofed Subject header matching a legitimate client certificate DN to bypass mTLS authentication and inject arbitrary events into protected EDA event streams.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat ansible automation platform 2.5 for rhel 8 red hat:red hat ansible automation platform 2.6 for rhel 9 red hat:red hat ansible automation platform 2.5 for rhel 9 red hat:red hat ansible automation platform 2.7 red hat:red hat ansible automation platform 2.6