Red HatCVE-2026-5136
Red Hat Satellite 6: privilege escalation
High8.8CVE-2026-5136 · Published Jul 1, 2026 · updated Jul 9, 2026
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-266
- www.cve.org/CVERecord?id=CVE-2026-5136
- nvd.nist.gov/vuln/detail/CVE-2026-5136
- access.redhat.com/errata/RHSA-2026:34365
- access.redhat.com/errata/RHSA-2026:34366
- access.redhat.com/errata/RHSA-2026:34367
- access.redhat.com/errata/RHSA-2026:34368
- access.redhat.com/security/cve/CVE-2026-5136
- bugzilla.redhat.com/show_bug.cgi?id=2452970
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 1 | Red Hat Satellite 6: improper access control | Medium6.5 | No fix yet |
| Jul 1 | Red Hat Satellite 6: information disclosure | Medium4.3 | No fix yet |
| Jul 1 | Red Hat Satellite 6: information disclosure | Medium6.5 | No fix yet |
| Jul 1 | Red Hat Enterprise Linux: null pointer dereference | Medium6.5 | No fix yet |
| Jul 1 | Red Hat Enterprise Linux: resource exhaustion | Medium5.5 | No fix yet |
| Jul 1 | Red Hat Feast Feature Server: denial of service | Critical9.1 | 0.59.0 |