CVE-2026-12423
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Summary
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.23-1.el8sat < * | unaffected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.23-1.el9sat < * | unaffected |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.25-1.el9sat < * | unaffected |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0.14-1.el9sat < * | unaffected |
Weaknesses
- CWE-306: Missing Authentication for Critical Function
Workarounds
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: yes
- Technical Impact: partial
References
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/errata/RHSA-2026:74504
- https://access.redhat.com/errata/RHSA-2026:74506
- https://access.redhat.com/security/cve/CVE-2026-12423
- https://bugzilla.redhat.com/show_bug.cgi?id=2488956
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.