#1147729 ansible: CVE-2026-87872

Package:
src:ansible
Source:
src:ansible
Submitter:
Moritz Mühlenhoff
Date:
2026-09-14 19:05:05 UTC
Severity:
normal
Tags:
#1147729#5
Date:
2026-09-14 17:41:06 UTC
From:
To:
Hi,

The following vulnerability was published for ansible.

CVE-2026-87872[0]:
| A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of
| the community.general Ansible collection. The shared OCAPI request
| helper disables TLS certificate validation on every request and the
| modules expose no parameter to re-enable it, while sending HTTP
| Basic-Auth credentials to an https endpoint. An attacker positioned
| on the network path between the Ansible controller and the OCAPI-
| managed storage/enclosure device can present any certificate,
| intercept the session, capture the credentials, and tamper with
| responses.

https://bugzilla.redhat.com/show_bug.cgi?id=2530988 is the only
reference which is sadly private.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87872
https://www.cve.org/CVERecord?id=CVE-2026-87872

Please adjust the affected versions in the BTS as needed.