PT-2026-89097 · Red Hat · Red Hat Ceph Storage 5+3

CVE-2026-87872

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

6.8

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
A flaw was found in the OCAPI modules (ocapi command, ocapi info) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-87872

Affected Products

Red Hat Ceph Storage 5
Red Hat Ceph Storage 9
Red Hat Openstack Platform 17.1
Red Hat Openstack Platform 18.0