CVE-2026-12540: Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter

Published Jun 17, 2026
·
Updated

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetchlog task. The requestid parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.

Other sources

Description

A command injection vulnerability exists in the foreman-rake errors:fetchlog task within Red Hat Satellite. The requestid parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.

Impact

Successful exploitation allows a restricted user to escalate privileges to the foreman user and subsequently to root across all managed hosts, Organizations, and Locations. This represents a complete compromise of the Red Hat Satellite server and the entire infrastructure it manages.

Recommendations

Validate Input: Sanitize the requestid parameter to ensure it only contains alphanumeric characters and dashes, rejecting any input containing shell metacharacters.

Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation (e.g., using Open3.capture3 with separate arguments in Ruby). Specifically, the following code in lib/tasks/errors.rake file should be replaced with something like this:

--------------------------------------------------------------------------------

// Vulnerable code

result = grep "#{requestid}" "#{filepath}"

— Red Hat

Affected Software

13 affected components
Foreman Foreman
Red Hat Red Hat Satellite
All of the following
redhat Satellite>=6.16<6.16.4
Any of the following
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
All of the following
redhat Satellite>=6.17<6.17.12
redhat Enterprise Linux=9.0
All of the following
redhat Satellite>=6.19<6.19.5
redhat Enterprise Linux=9.0
theforeman foreman
All of the following
redhat Satellite>=6.18<6.18.10
redhat Enterprise Linux=9.0
redhat Satellite=6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Foreman to a version that resolves this vulnerability.

    Fixed in 3.19.2
  2. Upgrade

    Upgrade Foreman to a version that resolves this vulnerability.

    Fixed in 5.0.1
  3. Configuration

    Replace shell-string interpolation in system calls with array-based arguments, such as using Open3.capture3 with separate Ruby arguments.

    Foreman foreman-rake errors:fetch_log task request_id command argument handling = array-based arguments
  4. Configuration

    Sanitize and validate the request_id parameter, rejecting any input containing shell metacharacters.

    Foreman foreman-rake errors:fetch_log task request_id input validation = alphanumeric characters and dashes only

Event History

Jun 17, 2026
Data Sourced
via Red Hat·04:44 PM
DescriptionSeverityAffected Software
Oct 1, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who is realistically exposed to exploitation?

Systems are exposed if a user has sudo permission to run the foreman-rake errors:fetch_log task. The issue is locally exploitable and requires high privileges; it is not described as remotely exploitable without prior access.

2

What does an attacker need to supply to exploit the issue?

The attacker needs control of the request_id parameter passed to the rake task. Shell metacharacters such as semicolons, quotes, or pipes can be used to escape the intended command and execute arbitrary code.

3

What is the likely impact after successful exploitation?

A restricted user can escalate to the foreman user and subsequently to root. The described impact includes complete compromise of the Red Hat Satellite server and its managed hosts, Organizations, and Locations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203