Red Hat Satellite 6: insecure direct object reference
Medium4.3CVE-2026-79654 · Published Aug 26, 2026 · updated Sep 23, 2026
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
| all versions | No fix yet | |
| all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 26 | A flaw was found in the ipa_getkeytab module of the community.general Ansible... | Medium5.5 | No fix yet |
| Aug 26 | Red Hat Seattle FilmWorks plugin: integer overflow | Medium5.5 | No fix yet |
| Aug 25 | Red Hat Enterprise Linux: type confusion | Medium5.7 | No fix yet |
| Aug 25 | Red Hat Enterprise Linux: stack buffer overflow | High7.6 | No fix yet |
| Aug 25 | Red Hat file-xwd plugin: out-of-bounds read | Medium4.4 | No fix yet |
| Aug 25 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing | Medium5.3 | No fix yet |