Red HatCVE-2026-56097
Red Hat Satellite 6: SQL injection
Medium6.5CVE-2026-56097 · Published Oct 1, 2026 · updated Oct 6, 2026
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-89
- www.cve.org/CVERecord?id=CVE-2026-56097
- nvd.nist.gov/vuln/detail/CVE-2026-56097
- access.redhat.com/errata/RHSA-2026:74503
- access.redhat.com/errata/RHSA-2026:74504
- access.redhat.com/errata/RHSA-2026:74505
- access.redhat.com/errata/RHSA-2026:74506
- access.redhat.com/security/cve/CVE-2026-56097
- bugzilla.redhat.com/show_bug.cgi?id=2490543
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium5.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium6.7 | No fix yet |
| Oct 1 | Red Hat Build of Keycloak: information disclosure | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Foreman. This vulnerability: information disclosure | Critical9.1 | No fix yet |