Red HatCVE-2026-12545
Red Hat Satellite 6: command injection
Medium6.7CVE-2026-12545 · Published Oct 1, 2026 · updated Oct 2, 2026
A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-78
- www.cve.org/CVERecord?id=CVE-2026-12545
- nvd.nist.gov/vuln/detail/CVE-2026-12545
- access.redhat.com/errata/RHSA-2026:74503
- access.redhat.com/errata/RHSA-2026:74504
- access.redhat.com/errata/RHSA-2026:74505
- access.redhat.com/errata/RHSA-2026:74506
- access.redhat.com/security/cve/CVE-2026-12545
- bugzilla.redhat.com/show_bug.cgi?id=2489993
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: SQL injection | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium5.3 | No fix yet |
| Oct 1 | Red Hat Build of Keycloak: information disclosure | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Foreman. This vulnerability: information disclosure | Critical9.1 | No fix yet |