CVE-2025-9572: Foreman: satellite: graphql api permission bypass leads to information disclosure

Published Aug 29, 2025
·
Updated

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

Other sources

The GraphQL /api/graphql endpoint returns all locations regardless of the requesting user's permissions, while the REST API /api/v2/locations correctly filters locations based on user access rights.

Red Hat

Affected Software

11 affected components
Foreman Foreman
theforeman foreman>=1.22.0<3.16.2
redhat Satellite=6.15
redhat Satellite=6.16
redhat Satellite=6.17
redhat Satellite=6.18
redhat Satellite Capsule=6.15
redhat Satellite Capsule=6.16
redhat Satellite Capsule=6.17
redhat Satellite Capsule=6.18
redhat Enterprise Linux=9.0

Event History

Aug 29, 2025
Data Sourced
via Red Hat·06:24 AM
DescriptionSeverityAffected Software
Feb 27, 2026
CVE Published
via MITRE·07:28 AM
Data Sourced
via MITRE·07:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-9572?

CVE-2025-9572 is classified as a high severity vulnerability due to the potential for unauthorized access to sensitive metadata.

2

How do I fix CVE-2025-9572?

To fix CVE-2025-9572, update your Foreman installation to the latest version that addresses the issue.

3

What type of vulnerability is CVE-2025-9572?

CVE-2025-9572 is an authorization flaw that allows low-privileged users to bypass permissions in the GraphQL API.

4

Which versions of Foreman are affected by CVE-2025-9572?

CVE-2025-9572 affects all versions of Foreman that utilize the vulnerable GraphQL API without proper access controls.

5

What impact does CVE-2025-9572 have on data security?

CVE-2025-9572 could lead to unauthorized information disclosure, allowing users to view sensitive metadata they are not permitted to access.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203