Back

MEDIUM

Foreman: command injection in foreman-tail

Published Oct 1, 2026

Description

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.

Affected products

Remediation

Vendor solution

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Red Hat statement

Successful exploitation of this issue allows a local attacker to escape restricted shells and execute arbitrary commands on the Satellite server. Consequently, the attacker could access sensitive information that could lead to remote code execution (RCE) and lateral movement across the managed infrastructure.

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Jun 17, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Moderate
Public date Oct 1, 2026