Skip to content
Red HatCVE-2026-5142

Red Hat Satellite 6: information disclosure

Medium6.5CVE-2026-5142 · Published Jul 1, 2026 · updated Jul 9, 2026

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Satellite 6
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat Satellite 6: improper access control
Medium6.5Jul 1
Red Hat Satellite 6: information disclosure
Medium4.3Jul 1
Red Hat Enterprise Linux: null pointer dereference
Medium6.5Jul 1
Red Hat Enterprise Linux: resource exhaustion
Medium5.5Jul 1
Red Hat Feast Feature Server: denial of service
Critical9.1Jul 1
Red Hat Satellite 6: privilege escalation
High8.8Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.