CVE-2026-12544: Foreman: ssti and insecure deserialization in foreman-rake configuration

Published Jun 17, 2026
·
Updated

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.

Other sources

Description

The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a Multi-Stage Execution Chain that allows for both Server-Side Template Injection (SSTI) and Insecure Deserialization.

The vulnerability execution chain has two stages:

Template Injection (ERB): The first stage uses ERB.new(...).result. This evaluates the file as a Ruby template. Any code inside <%= ... %> is executed by the Ruby interpreter to generate a string. This is an SSTI that allows for direct OS command injection.

Insecure Deserialization (YAML): The second stage takes the rendered string and passes it to YAML.load. Because this is an unsafe parser, it allows for object injection. Even if an attacker cannot use ERB tags, they can craft YAML that instantiates malicious Ruby "gadget chains" to achieve code execution.

The vulnerability exists in two different application functionalities, thus it can be exploited in two different ways:

Primary config:

SETTINGS.merge! YAML.load(ERB.new(File.read(settingsfile)).result) allows an attacker to craft a malicious /etc/foreman-maintain/foremanmaintain.yml file that will be loaded and executed by foreman-rake on start.

Plugins config:

SETTINGS.merge! YAML.load(ERB.new(File.read(f)).result) allows an attacker to craft a malicious file that will be executed from /usr/share/foreman/config/settings.plugins.d/ by foreman-rake on start.

Impact

Indirect Triggering & Privileged RCE: foreman-rake exposes underlying execution primitives that higher-level orchestration tools (like foreman-maintain or foreman-installer) rely on to interact with the application. Because these tools implicitly pass commands down, the vulnerability can be triggered indirectly during routine administrative operations, resulting in Remote Code Execution (RCE) in a high-trust context (often foreman or root).

Total Infrastructure Compromise: Compromising the management plane (Satellite server) allows an attacker to pivot and execute arbitrary code across all Satellite Managed Hosts.

Supply Chain Risk: While direct local exploitation requires prior root access, this flaw presents a critical supply chain risk. An adversary could distribute malicious plugins or compromised configuration files through public repositories (e.g., RubyGems, GitHub). Note: The CVSS vector and severity are based on this supply chain attack vector.

RECOMMENDATIONS

Replace YAML.load with YAML.safeload(content, permittedclasses: [Symbol]) in both locations in settings.rb.

Remove the ERB.new().result evaluation. Configuration files must be treated as static data, never as executable templates.

— Red Hat

Affected Software

1 affected component
Foreman Foreman

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Remove the ERB.new().result evaluation so configuration files are treated as static data rather than executable Ruby templates.

    foreman-rake initialization logic in /usr/share/foreman/config/settings.rb ERB.new(...).result evaluation = removed
  2. Configuration

    Replace YAML.load with YAML.safe_load(content, permitted_classes: [Symbol]) in both locations in settings.rb.

    foreman-rake configuration loading in /usr/share/foreman/config/settings.rb YAML.load = YAML.safe_load(content, permitted_classes: [Symbol])

Event History

Jun 17, 2026
Data Sourced
via Red Hat·05:03 PM
DescriptionSeverityAffected Software
Oct 1, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203