What is CVE-2026-12383?
A vulnerability (CVE-2026-12383) was found in the Event-Driven Ansible (EDA) server where the ExternalEventStreamViewSet uses overly permissive access controls and relies solely on the Subject HTTP header value for mTLS authentication without verifying the header's origin. Affected EDA server administrators should ensure proper origin verification and strengthen authentication mechanisms.
Azərbaycanca: Event-Driven Ansible (EDA) server-də CVE-2026-12383 zəifliyi aşkar edilib. 'ExternalEventStreamViewSet' komponenti geniş icazə nəzarətləri ilə konfiqurasiya olunub və yalnız 'Subject HTTP header' dəyərinə etibar edərək mTLS autentifikasiyasını düzgün yoxlamır. Təsirə məruz qalan EDA server sahibləri header mənşəyinin doğrulanmasını təmin etməli və autentifikasiya mexanizmlərini sərtləşdirməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which component does the CVE-2026-12383 vulnerability affect in the Event-Driven Ansible (EDA) server?
The CVE-2026-12383 vulnerability affects the ExternalEventStreamViewSet component.
What is the main authentication issue with the CVE-2026-12383 vulnerability?
The vulnerability stems from the server relying solely on the Subject HTTP header value for mTLS authentication without properly verifying the header's origin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.