Skip to content
Red HatCVE-2026-5138

Red Hat Satellite 6: information disclosure

Medium4.3CVE-2026-5138 · Published Jul 1, 2026 · updated Jul 9, 2026

A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing authorization checks. This allows the user to leak sensitive infrastructure metadata, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs, from organizations and locations they are not authorized to access.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Satellite 6
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: improper access control
Medium6.5Jul 1
Red Hat Satellite 6: information disclosure
Medium6.5Jul 1
Red Hat Enterprise Linux: null pointer dereference
Medium6.5Jul 1
Red Hat Enterprise Linux: resource exhaustion
Medium5.5Jul 1
Red Hat Feast Feature Server: denial of service
Critical9.1Jul 1
Red Hat Satellite 6: privilege escalation
High8.8Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.