Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
Red HatCVE-2026-96658

Red Hat Foreman: remote code execution

Critical9.9CVE-2026-96658 · Published Oct 1, 2026 · updated Oct 2, 2026

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

Red Hat advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat 389-ds-base: resource exhaustion
High7.5Oct 1
Red Hat Satellite 6: SQL injection
Medium6.5Oct 1
Red Hat Satellite 6: observable discrepancy
Medium4.3Oct 1
Red Hat Satellite 6: command injection
Medium5.3Oct 1
Red Hat Satellite 6: command injection
Medium6.7Oct 1
Red Hat Build of Keycloak: information disclosure
Medium6.5Oct 1