Back

CRITICAL

Foreman: excessive permissions for viewer role on preview

Published Oct 1, 2026

Description

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.

Affected products

Remediation

Red Hat statement

This vulnerability is rated as having an Important security impact because authenticated users assigned restricted Viewer permissions can bypass role-based access controls to retrieve sensitive host credentials. In Red Hat Satellite environments, querying template preview endpoints exposes critical host attributes that should remain restricted to higher-privileged administrators. Furthermore, if template safemode protection is disabled or circumvented, this authorization flaw can escalate to arbitrary remote code execution under the identity of the foreman service account.

Metrics

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 1, 2026
Updated Oct 1, 2026
Reserved Sep 23, 2026
NVD
Status Awaiting Analysis
Modified Oct 2, 2026
Red Hat
Severity Important
Public date Oct 1, 2026