Skip to content
Red HatCVE-2026-5135

Red Hat Satellite 6: improper access control

Medium6.5CVE-2026-5135 · Published Jul 1, 2026 · updated Jul 9, 2026

A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Satellite 6
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: information disclosure
Medium4.3Jul 1
Red Hat Satellite 6: information disclosure
Medium6.5Jul 1
Red Hat Enterprise Linux: null pointer dereference
Medium6.5Jul 1
Red Hat Enterprise Linux: resource exhaustion
Medium5.5Jul 1
Red Hat Feast Feature Server: denial of service
Critical9.1Jul 1
Red Hat Satellite 6: privilege escalation
High8.8Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.