Red HatCVE-2026-12540
Red Hat Satellite 6: command injection
High8.2CVE-2026-12540 · Published Oct 1, 2026 · updated Oct 6, 2026
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
- www.cve.org/CVERecord?id=CVE-2026-12540
- nvd.nist.gov/vuln/detail/CVE-2026-12540
- access.redhat.com/errata/RHSA-2026:74503
- access.redhat.com/errata/RHSA-2026:74504
- access.redhat.com/errata/RHSA-2026:74505
- access.redhat.com/errata/RHSA-2026:74506
- access.redhat.com/security/cve/CVE-2026-12540
- bugzilla.redhat.com/show_bug.cgi?id=2489969
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: SQL injection | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium5.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium6.7 | No fix yet |
| Oct 1 | Red Hat Build of Keycloak: information disclosure | Medium6.5 | No fix yet |