Back

CRITICAL

Foreman: safemode bypass leading to rce

Published Oct 1, 2026

Description

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

Affected products

Remediation

Red Hat statement

Red Hat Product Security rates this vulnerability as having a Critical security impact because an authenticated user with minimal read permissions can achieve arbitrary remote code execution on the underlying Satellite server. In Red Hat Satellite deployments, Foreman relies on a restricted sandbox to safely render templates. Flaws in this evaluation mechanism allow adversaries with baseline view privileges to bypass isolation and execute unauthorized commands directly on the host system.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 1, 2026
Updated Oct 2, 2026
Reserved Sep 23, 2026
CISA Vulnrichment
Updated Oct 1, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Critical
Public date Oct 1, 2026