community.general Ansible collection. The shared OCAPI request helper disables
TLS certificate validation on every request and the modules expose no parameter
to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint.
An attacker positioned on the network path between the Ansible controller and the
OCAPI-managed storage/enclosure device can present any certificate, intercept the
session, capture the credentials, and tamper with responses.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Until fixed, only run the OCAPI modules against devices reached over a fully trusted/isolated management network path (no untrusted on-path segments), since certificate validation cannot be enabled. Treat the OCAPI Basic-Auth credentials as exposable in transit and rotate if MITM exposure is suspected.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 09 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses. | |
| Title | Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure | |
| First Time appeared |
Redhat
Redhat ceph Storage Redhat openstack |
|
| Weaknesses | CWE-295 | |
| CPEs | cpe:/a:redhat:ceph_storage:5 cpe:/a:redhat:ceph_storage:9 cpe:/a:redhat:openstack:17.1 cpe:/a:redhat:openstack:18.0 |
|
| Vendors & Products |
Redhat
Redhat ceph Storage Redhat openstack |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-09T16:06:27.744Z
Reserved: 2026-09-09T13:36:20.508Z
Link: CVE-2026-87872
No data.
Status : Received
Published: 2026-09-09T17:17:52.960
Modified: 2026-09-09T17:17:52.960
Link: CVE-2026-87872
No data.
OpenCVE Enrichment
No data.
