CVE-2026-96658

Summary

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

Affected Software

VendorProductVersion RangeStatus
Red HatRed Hat Satellite 6.16 for RHEL 80:1.5.0-2.el8sat < *unaffected
Red HatRed Hat Satellite 6.16 for RHEL 90:1.5.0-2.el9sat < *unaffected
Red HatRed Hat Satellite 6.18 for RHEL 90:1.5.0-2.el9sat < *unaffected
Red HatRed Hat Satellite 6.19 for RHEL 90:3.18.0.14-1.el9sat < *unaffected

Weaknesses

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References