Red HatCVE-2026-12541
Red Hat Satellite 6: command injection
High8.2CVE-2026-12541 · Published Oct 1, 2026 · updated Oct 2, 2026
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
- www.cve.org/CVERecord?id=CVE-2026-12541
- nvd.nist.gov/vuln/detail/CVE-2026-12541
- access.redhat.com/errata/RHSA-2026:74503
- access.redhat.com/errata/RHSA-2026:74504
- access.redhat.com/errata/RHSA-2026:74505
- access.redhat.com/errata/RHSA-2026:74506
- access.redhat.com/security/cve/CVE-2026-12541
- bugzilla.redhat.com/show_bug.cgi?id=2489970
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: SQL injection | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium5.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium6.7 | No fix yet |
| Oct 1 | Red Hat Build of Keycloak: information disclosure | Medium6.5 | No fix yet |