VDB
CVE-2026-79654
CVE-2026-79654
PUBLISHED
CVSS 4.3 MEDIUM
Reported by redhat · Published August 26, 2026
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.
Risk Scores
CVSS 3.1
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:4.14.0.23-1.el8sat |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:4.14.0.23-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.16.0.20-1.el9sat |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:4.18.0.24-1.el9sat |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:4.20.0.11-1.el9sat |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:4.14.0.23-1.el8sat, 0:4.14.0.23-1.el8sat |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:4.14.0.23-1.el9sat, 0:4.14.0.23-1.el9sat |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:4.20.0.11-1.el9sat, 0:4.20.0.11-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.16.0.20-1.el9sat |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:4.18.0.24-1.el9sat, 0:4.18.0.24-1.el9sat |
| Red Hat | Red Hat Satellite 6 | |
| Red Hat | Red Hat Satellite 6 |
Timeline
- Aug 26, 2026 EPSS Score
- Aug 26, 2026 Coalition ESS Score
- Aug 26, 2026 CVE Published
- Aug 27, 2026 EPSS Score
- Sep 1, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
References
- RHSA-2026:74503 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74504 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74505 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74506 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2523348 issue-trackingx_refsource_REDHAT