A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of the
community.general Ansible collection. The shared OCAPI request helper disables
TLS certificate validation on every request and the modules expose no parameter
to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint.
An attacker positioned on the network path between the Ansible controller and the
OCAPI-managed storage/enclosure device can present any certificate, intercept the
session, capture the credentials, and tamper with responses.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 17:17
Updated : 2026-09-14 14:17
NVD link : CVE-2026-87872
Mitre link : CVE-2026-87872
CVE.ORG link : CVE-2026-87872
JSON object : View
Products Affected
No product.
CWE
CWE-295
Improper Certificate Validation
