CVE-2026-56098

Summary

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Satellite 6.16 for RHEL 80:4.14.0.23-1.el8sat < *unaffected
Red HatRed Hat Satellite 6.16 for RHEL 90:4.14.0.23-1.el9sat < *unaffected
Red HatRed Hat Satellite 6.18 for RHEL 90:4.18.0.24-1.el9sat < *unaffected
Red HatRed Hat Satellite 6.19 for RHEL 90:4.20.0.11-1.el9sat < *unaffected

Weaknesses

  • CWE-203: Observable Discrepancy

Workarounds

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References