Skip to content
Red HatCVE-2026-5136

Red Hat Satellite 6: privilege escalation

High8.8CVE-2026-5136 · Published Jul 1, 2026 · updated Jul 9, 2026

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Satellite 6
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: improper access control
Medium6.5Jul 1
Red Hat Satellite 6: information disclosure
Medium4.3Jul 1
Red Hat Satellite 6: information disclosure
Medium6.5Jul 1
Red Hat Enterprise Linux: null pointer dereference
Medium6.5Jul 1
Red Hat Enterprise Linux: resource exhaustion
Medium5.5Jul 1
Red Hat Feast Feature Server: denial of service
Critical9.1Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.