Foreman: safemode bypass leading to rce
Published Oct 1, 2026
9.9
CRITICALCVSS 3.1
Description
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.
Affected products
No data.
No data.
No data.
Red Hat Satellite 6.16 for RHEL 8
rubygem-safemode-0:1.5.0-2.el8sat
Fixed · RHSA-2026:74506
Red Hat Satellite 6.16 for RHEL 9
rubygem-safemode-0:1.5.0-2.el9sat
Fixed · RHSA-2026:74506
Red Hat Satellite 6.18 for RHEL 9
rubygem-safemode-0:1.5.0-2.el9sat
Fixed · RHSA-2026:74504
Red Hat Satellite 6.19 for RHEL 9
foreman-0:3.18.0.14-1.el9sat
Fixed · RHSA-2026:74503
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.16 for RHEL 8 | rubygem-safemode-0:1.5.0-2.el8sat | Fixed | RHSA-2026:74506 |
| Red Hat Satellite 6.16 for RHEL 9 | rubygem-safemode-0:1.5.0-2.el9sat | Fixed | RHSA-2026:74506 |
| Red Hat Satellite 6.18 for RHEL 9 | rubygem-safemode-0:1.5.0-2.el9sat | Fixed | RHSA-2026:74504 |
| Red Hat Satellite 6.19 for RHEL 9 | foreman-0:3.18.0.14-1.el9sat | Fixed | RHSA-2026:74503 |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security rates this vulnerability as having a Critical security impact because an authenticated user with minimal read permissions can achieve arbitrary remote code execution on the underlying Satellite server. In Red Hat Satellite deployments, Foreman relies on a restricted sandbox to safely render templates. Flaws in this evaluation mechanism allow adversaries with baseline view privileges to bypass isolation and execute unauthorized commands directly on the host system.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed Oct 1, 2026 · SSVC 2.0.3
No EPSS score for this CVE.
References (7)
- https://access.redhat.com/errata/RHSA-2026:74503 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74504 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74506 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-96658 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2534185 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-96658
- https://www.cve.org/CVERecord?id=CVE-2026-96658
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:74503 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:74504 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:74506 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-96658 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2534185 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-96658 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-96658 |
Change history (0)
No recorded changes yet.