Back

HIGH

Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation

Published Jul 1, 2026

Description

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 1, 2026
Updated Jul 2, 2026
Reserved Mar 30, 2026
CISA Vulnrichment
Updated Jul 1, 2026
NVD
Status Analyzed
Modified Jul 9, 2026
Red Hat
Severity Important
Public date Jul 1, 2026