CVE-2026-12544
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Summary
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Satellite 6.16 for RHEL 8 | 0:3.12.0.23-1.el8sat < * | unaffected |
| Red Hat | Red Hat Satellite 6.16 for RHEL 9 | 0:3.12.0.23-1.el9sat < * | unaffected |
| Red Hat | Red Hat Satellite 6.18 for RHEL 9 | 0:3.16.0.25-1.el9sat < * | unaffected |
| Red Hat | Red Hat Satellite 6.19 for RHEL 9 | 0:3.18.0.14-1.el9sat < * | unaffected |
Weaknesses
- CWE-502: Deserialization of Untrusted Data
Workarounds
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/errata/RHSA-2026:74504
- https://access.redhat.com/errata/RHSA-2026:74506
- https://access.redhat.com/security/cve/CVE-2026-12544
- https://bugzilla.redhat.com/show_bug.cgi?id=2489992
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.