CVE-2026-12541: Foreman: command injection in foreman-rake database tasks

Published Jun 17, 2026
·
Updated

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:importdump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Other sources

Description

OS command injection vulnerabilities exist in the foreman-rake db:dump and db:importdump tasks within Red Hat Satellite (Foreman). The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution.

An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Impact

Exploitation allows a restricted user to escalate privileges to the foreman account and execute arbitrary commands . This grants control over the Satellite database and configurations, enabling lateral movement and full root Remote Code Execution on all managed hosts (as demonstrated in F-03 Command Injection in foreman-rake errors:fetchlog via requestid Parameter).

Recommendations

Validate Input: Implement strict validation for both the destination and file parameters in the Rake tasks to ensure they only contain valid filesystem paths and no shell metacharacters before processing.

Use Argument Arrays: Modify the underlying code to use non-shell execution methods (e.g., passing arguments as an array to system() or exec()) to prevent shell interpretation.

— Red Hat

Affected Software

1 affected component
Foreman Foreman

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Modify the foreman-rake database tasks to use non-shell execution methods, such as passing arguments as an array to Ruby system() or using exec(), to prevent shell interpretation.

  2. Compensating control

    Strictly validate the destination parameter in db:dump and the file parameter in db:import_dump so they contain only valid filesystem paths and no shell metacharacters before processing.

Event History

Jun 17, 2026
Data Sourced
via Red Hat·04:46 PM
DescriptionSeverityAffected Software
Oct 1, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically exploit this issue?

A user who already has permission to execute foreman-rake can exploit it, including a user granted access through a restricted sudo configuration. The issue is therefore primarily relevant where untrusted or lower-privileged users can run these database tasks.

2

Which operations are vulnerable?

The vulnerable operations are the foreman-rake db:dump task, through its destination parameter, and the db:import_dump task, through its file parameter. Supplying shell metacharacters in those path values can append commands passed to Ruby's system() call.

3

What is the impact of successful exploitation?

An attacker can escalate to the foreman account and execute arbitrary commands. This can provide control over Satellite database contents and configurations.

4

What should be restricted while remediation is pending?

Restrict access to foreman-rake, particularly db:dump and db:import_dump, and review restricted sudo rules that allow users to invoke it. Do not allow untrusted users to supply destination or file parameter values to these tasks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203