Red HatCVE-2026-96659
Red Hat Foreman. This vulnerability: information disclosure
Critical9.1CVE-2026-96659 · Published Oct 1, 2026 · updated Oct 6, 2026
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-267
- www.cve.org/CVERecord?id=CVE-2026-96659
- nvd.nist.gov/vuln/detail/CVE-2026-96659
- access.redhat.com/errata/RHSA-2026:74503
- access.redhat.com/errata/RHSA-2026:74504
- access.redhat.com/errata/RHSA-2026:74505
- access.redhat.com/errata/RHSA-2026:74506
- access.redhat.com/security/cve/CVE-2026-96659
- bugzilla.redhat.com/show_bug.cgi?id=2536844
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Oct 1 | Red Hat 389-ds-base: resource exhaustion | High7.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: SQL injection | Medium6.5 | No fix yet |
| Oct 1 | Red Hat Satellite 6: observable discrepancy | Medium4.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium5.3 | No fix yet |
| Oct 1 | Red Hat Satellite 6: command injection | Medium6.7 | No fix yet |
| Oct 1 | Red Hat Build of Keycloak: information disclosure | Medium6.5 | No fix yet |