VDB
CVE-2026-1961
CVE-2026-1961
PUBLISHED
CVSS 8 HIGH
A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.
EPSS 0.04% · 12.1th percentile
Risk Scores
CVSS 3.1
8
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.04%
12.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.12-1.el9sat, 0:3.16.0.12-1.el9sat, * |
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.14-1.el8sat, 0:3.12.0.14-1.el8sat, * |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | *, 0:0.4.3-1.el9sat, * |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.27.10-2.el9pc, 0:3.27.10-2.el9pc, 0:3.27.10-2.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.14-1.el9sat, 0:3.14.0.14-1.el9sat, 0:3.14.0.14-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.0.3-4.el9sat, 0:0.0.3-4.el9sat, * |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.14-1.el9sat, 0:3.12.0.14-1.el9sat, 0:3.12.0.14-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.1.23-0.3.el9pc, 0:0.1.23-0.3.el9pc, 0:0.1.23-0.3.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:6.17.7-1.el9sat, 0:6.17.7-1.el9sat, 0:6.17.7-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.5.1-1.el9sat, 0:1.5.1-1.el9sat, 0:1.5.1-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | *, *, * |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.13.0-1.el9sat, 0:0.13.0-1.el9sat, 0:0.13.0-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | *, 0:4.16.0.14-1.el9sat, 0:4.16.0.14-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.2.28-0.1.el9pc, 0:4.2.28-0.1.el9pc, 0:4.2.28-0.1.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:2.22.3-1.el9pc, 0:2.22.3-1.el9pc, 0:2.22.3-1.el9pc |
Exploit Intelligence
- CIRCL seen: CVE-2026-1961 (circl-sighting)
- CIRCL seen: CVE-2026-1961 (circl-sighting)
- CIRCL seen: CVE-2026-1961 (circl-sighting)
- http://www.openwall.com/lists/oss-security/2026/03/27/3 (circl)
- RHSA-2026:5968 (circl)
- RHSA-2026:5970 (circl)
- RHSA-2026:5971 (circl)
- https://access.redhat.com/security/cve/CVE-2026-1961 (circl)
- RHBZ#2437036 (circl)
Timeline
- Mar 26, 2026 CVE Published
- Mar 26, 2026 PoC Published
- Mar 26, 2026 PoC Published
- Mar 27, 2026 Coalition ESS Score
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Security Advisory
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Security Advisory
- Mar 27, 2026 Distribution Patch
- Mar 27, 2026 Security Advisory
- Mar 27, 2026 PoC Published
- Mar 27, 2026 CVE Updated
References
- RHSA-2026:5968 vendor-advisory
- RHSA-2026:5970 vendor-advisory
- RHSA-2026:5971 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2026-1961 vdb
- RHBZ#2437036 issue
- http://www.openwall.com/lists/oss-security/2026/03/27/3 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-1961 advisory