Foreman: excessive permissions for viewer role on preview
Published Oct 1, 2026
9.1
CRITICALCVSS 3.1
Description
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
Affected products
No data.
No data.
No data.
Red Hat Satellite 6.16 for RHEL 8
foreman-0:3.12.0.23-1.el8sat
Fixed · RHSA-2026:74506
Red Hat Satellite 6.16 for RHEL 9
foreman-0:3.12.0.23-1.el9sat
Fixed · RHSA-2026:74506
Red Hat Satellite 6.18 for RHEL 9
foreman-0:3.16.0.25-1.el9sat
Fixed · RHSA-2026:74504
Red Hat Satellite 6.19 for RHEL 9
foreman-0:3.18.0.14-1.el9sat
Fixed · RHSA-2026:74503
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Satellite 6.16 for RHEL 8 | foreman-0:3.12.0.23-1.el8sat | Fixed | RHSA-2026:74506 |
| Red Hat Satellite 6.16 for RHEL 9 | foreman-0:3.12.0.23-1.el9sat | Fixed | RHSA-2026:74506 |
| Red Hat Satellite 6.18 for RHEL 9 | foreman-0:3.16.0.25-1.el9sat | Fixed | RHSA-2026:74504 |
| Red Hat Satellite 6.19 for RHEL 9 | foreman-0:3.18.0.14-1.el9sat | Fixed | RHSA-2026:74503 |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability is rated as having an Important security impact because authenticated users assigned restricted Viewer permissions can bypass role-based access controls to retrieve sensitive host credentials. In Red Hat Satellite environments, querying template preview endpoints exposes critical host attributes that should remain restricted to higher-privileged administrators. Furthermore, if template safemode protection is disabled or circumvented, this authorization flaw can escalate to arbitrary remote code execution under the identity of the foreman service account.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (7)
- https://access.redhat.com/errata/RHSA-2026:74503 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74504 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:74506 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-96659 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2536844 issue-trackingx_refsource_REDHATIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2026-96659
- https://www.cve.org/CVERecord?id=CVE-2026-96659
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:74503 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:74504 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:74506 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-96659 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2536844 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-96659 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-96659 |
Change history (0)
No recorded changes yet.