Foreman: command injection in foreman-tail
Published Oct 1, 2026
5.3
MEDIUMCVSS 3.1
Description
A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Satellite 6 | affected |
|
No data.
No data.
Red Hat Satellite 6.16 for RHEL 8
foreman-0:3.12.0.23-1.el8sat
Fixed · RHSA-2026:74506
Red Hat Satellite 6.16 for RHEL 9
foreman-0:3.12.0.23-1.el9sat
Fixed · RHSA-2026:74506
Red Hat Satellite 6.18 for RHEL 9
foreman-0:3.16.0.25-1.el9sat
Fixed · RHSA-2026:74504
Red Hat Satellite 6.19 for RHEL 9
foreman-0:3.18.0.14-1.el9sat
Fixed · RHSA-2026:74503
Red Hat Satellite 6
satellite:el8/foreman
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.16 for RHEL 8 | foreman-0:3.12.0.23-1.el8sat | Fixed | RHSA-2026:74506 |
| Red Hat Satellite 6.16 for RHEL 9 | foreman-0:3.12.0.23-1.el9sat | Fixed | RHSA-2026:74506 |
| Red Hat Satellite 6.18 for RHEL 9 | foreman-0:3.16.0.25-1.el9sat | Fixed | RHSA-2026:74504 |
| Red Hat Satellite 6.19 for RHEL 9 | foreman-0:3.18.0.14-1.el9sat | Fixed | RHSA-2026:74503 |
| Red Hat Satellite 6 | satellite:el8/foreman | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Red Hat statement
Successful exploitation of this issue allows a local attacker to escape restricted shells and execute arbitrary commands on the Satellite server. Consequently, the attacker could access sensitive information that could lead to remote code execution (RCE) and lateral movement across the managed infrastructure.
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (7)
- https://access.redhat.com/errata/RHSA-2026:74503 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74504 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74506 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-12542 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2489971 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-12542
- https://www.cve.org/CVERecord?id=CVE-2026-12542
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:74503 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:74504 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:74506 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-12542 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2489971 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-12542 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-12542 |
Change history (0)
No recorded changes yet.