VDB
CVE-2026-96659
CVE-2026-96659
PUBLISHED
CVSS 9.1 CRITICAL
Reported by redhat · Published October 1, 2026
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
Risk Scores
CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.23-1.el8sat |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.23-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0.22-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.2.13-1.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.1.62-1.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:5.3.1-2.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.6.0-1.el9pc |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:15.0.2-2.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:3.14.0-2.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:4.16.0.20-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:1.5.0-2.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:6.17.12-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:0.1.0-2.1.el9sat |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.25-1.el9sat |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0.14-1.el9sat |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0.14-1.el9sat, 0:3.18.0.14-1.el9sat, 0:3.18.0.14-1.el9sat |
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.23-1.el8sat, 0:3.12.0.23-1.el8sat, 0:3.12.0.23-1.el8sat |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.25-1.el9sat, 0:3.16.0.25-1.el9sat, 0:3.16.0.25-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:6.17.12-1.el9sat, 0:6.17.12-1.el9sat, 0:6.17.12-1.el9sat |
| Red Hat | Red Hat Satellite 6.17 for RHEL 9 | 0:15.0.2-2.el9sat, 0:15.0.2-2.el9sat, 0:15.0.2-2.el9sat |
…and 10 more
Timeline
- Oct 1, 2026 Coalition ESS Score
- Oct 1, 2026 CVE Published
- Oct 1, 2026 Distribution Patch
- Oct 1, 2026 Security Advisory
- Oct 2, 2026 EPSS Score
- Oct 3, 2026 EPSS Score
- Oct 4, 2026 Distribution Patch
- Oct 4, 2026 Security Advisory
- Oct 4, 2026 Distribution Patch
- Oct 4, 2026 Security Advisory
- Oct 4, 2026 Distribution Patch
- Oct 4, 2026 Security Advisory
References
- RHSA-2026:74503 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74504 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74505 vendor-advisoryx_refsource_REDHAT
- RHSA-2026:74506 vendor-advisoryx_refsource_REDHAT
- vdb-entryx_refsource_REDHAT
- RHBZ#2536844 issue-trackingx_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2026/10/07/1 url