Skip to content
Red HatCVE-2026-79654

Red Hat Satellite 6: insecure direct object reference

Medium4.3CVE-2026-79654 · Published Aug 26, 2026 · updated Sep 23, 2026

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Satellite 6
Product
all versionsNo fix yet
all versionsNo fix yet
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
A flaw was found in the ipa_getkeytab module of the community.general Ansible...
Medium5.5Aug 26
Red Hat Seattle FilmWorks plugin: integer overflow
Medium5.5Aug 26
Red Hat Enterprise Linux: type confusion
Medium5.7Aug 25
Red Hat Enterprise Linux: stack buffer overflow
High7.6Aug 25
Red Hat file-xwd plugin: out-of-bounds read
Medium4.4Aug 25
An algorithmic complexity flaw exists in libsoup's HTTP Range header processing
Medium5.3Aug 25

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.