CVE-2026-87872: Community.general: community.general: ocapi module_utils (ocapi_command, ocapi_info) hardcode validate_certs=false with no override, enabling tls man-in-the-middle and credential disclosure

Published Sep 9, 2026
·
Updated

A flaw was found in the OCAPI modules (ocapicommand, ocapiinfo) of the community.general Ansible collection. The shared OCAPI request helper disables TLS certificate validation on every request and the modules expose no parameter to re-enable it, while sending HTTP Basic-Auth credentials to an https endpoint. An attacker positioned on the network path between the Ansible controller and the OCAPI-managed storage/enclosure device can present any certificate, intercept the session, capture the credentials, and tamper with responses.

Affected Software

2 affected components
ansible_collections/community/general/ocapi_command
ansible_collections/community/general/ocapi_info

Event History

Sep 9, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Ansible environments that use the community.general ocapi_command or ocapi_info modules to connect over HTTPS to an OCAPI-managed storage or enclosure device are exposed. The attacker must be able to position themselves on the network path between the Ansible controller and that device.

2

Is a non-default setting required for exploitation?

No. The shared OCAPI request helper disables TLS certificate validation on every request, and these modules provide no parameter to enable validation. HTTPS connections made through the affected modules therefore accept an attacker-provided certificate.

3

What can an attacker obtain or change?

A network-path attacker can intercept HTTP Basic-Auth credentials sent by the modules and tamper with OCAPI responses. The reported impact includes high confidentiality and integrity impact, with no availability impact stated.

4

What can be done while a fix is unavailable?

Restrict and protect the network path between the Ansible controller and the OCAPI-managed device so an attacker cannot intercept that traffic. Because the modules offer no certificate-validation override, module configuration cannot restore TLS certificate verification.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203