CVE-2026-12540: Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetchlog task. The requestid parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
Other sources
Description
A command injection vulnerability exists in the foreman-rake errors:fetchlog task within Red Hat Satellite. The requestid parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
Impact
Successful exploitation allows a restricted user to escalate privileges to the foreman user and subsequently to root across all managed hosts, Organizations, and Locations. This represents a complete compromise of the Red Hat Satellite server and the entire infrastructure it manages.
Recommendations
Validate Input: Sanitize the requestid parameter to ensure it only contains alphanumeric characters and dashes, rejecting any input containing shell metacharacters.
Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation (e.g., using Open3.capture3 with separate arguments in Ruby). Specifically, the following code in lib/tasks/errors.rake file should be replaced with something like this:
--------------------------------------------------------------------------------
// Vulnerable code
result = grep "#{requestid}" "#{filepath}"
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Foremanto a version that resolves this vulnerability.Fixed in 3.19.2 - Upgrade
Upgrade
Foremanto a version that resolves this vulnerability.Fixed in 5.0.1 - Configuration
Replace shell-string interpolation in system calls with array-based arguments, such as using Open3.capture3 with separate Ruby arguments.
Foreman foreman-rake errors:fetch_log task request_id command argument handling = array-based arguments - Configuration
Sanitize and validate the request_id parameter, rejecting any input containing shell metacharacters.
Foreman foreman-rake errors:fetch_log task request_id input validation = alphanumeric characters and dashes only
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Systems are exposed if a user has sudo permission to run the foreman-rake errors:fetch_log task. The issue is locally exploitable and requires high privileges; it is not described as remotely exploitable without prior access.
What does an attacker need to supply to exploit the issue?
The attacker needs control of the request_id parameter passed to the rake task. Shell metacharacters such as semicolons, quotes, or pipes can be used to escape the intended command and execute arbitrary code.
What is the likely impact after successful exploitation?
A restricted user can escalate to the foreman user and subsequently to root. The described impact includes complete compromise of the Red Hat Satellite server and its managed hosts, Organizations, and Locations.