Red Hat Satellite 6: insecure direct object reference
Medium6.5CVE-2026-81658 · Published Aug 27, 2026 · updated Aug 28, 2026
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Satellite 6 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-639
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 27 | Red Hat gdk-pixbuf.: out-of-bounds write | Medium4.7 | No fix yet |
| Aug 27 | Red Hat rsyslog: buffer overflow | High7.5 | No fix yet |
| Aug 27 | Red Hat Undertow. A remote attacker: resource exhaustion | High7.5 | No fix yet |
| Aug 27 | Red Hat Satellite 6: insecure direct object reference | Medium5.4 | No fix yet |
| Aug 26 | A flaw was found in the ipa_getkeytab module of the community.general Ansible... | Medium5.5 | No fix yet |
| Aug 26 | Red Hat Seattle FilmWorks plugin: integer overflow | Medium5.5 | No fix yet |