CVE-2026-12541

Summary

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Satellite 6.16 for RHEL 80:3.12.0.23-1.el8sat < *unaffected
Red HatRed Hat Satellite 6.16 for RHEL 90:3.12.0.23-1.el9sat < *unaffected
Red HatRed Hat Satellite 6.18 for RHEL 90:3.16.0.25-1.el9sat < *unaffected
Red HatRed Hat Satellite 6.19 for RHEL 90:3.18.0.14-1.el9sat < *unaffected

Weaknesses

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Workarounds

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References