CVE-2026-12544: Foreman: ssti and insecure deserialization in foreman-rake configuration
A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.
Other sources
Description
The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a Multi-Stage Execution Chain that allows for both Server-Side Template Injection (SSTI) and Insecure Deserialization.
The vulnerability execution chain has two stages:
Template Injection (ERB): The first stage uses ERB.new(...).result. This evaluates the file as a Ruby template. Any code inside <%= ... %> is executed by the Ruby interpreter to generate a string. This is an SSTI that allows for direct OS command injection.
Insecure Deserialization (YAML): The second stage takes the rendered string and passes it to YAML.load. Because this is an unsafe parser, it allows for object injection. Even if an attacker cannot use ERB tags, they can craft YAML that instantiates malicious Ruby "gadget chains" to achieve code execution.
The vulnerability exists in two different application functionalities, thus it can be exploited in two different ways:
Primary config:
SETTINGS.merge! YAML.load(ERB.new(File.read(settingsfile)).result) allows an attacker to craft a malicious /etc/foreman-maintain/foremanmaintain.yml file that will be loaded and executed by foreman-rake on start.
Plugins config:
SETTINGS.merge! YAML.load(ERB.new(File.read(f)).result) allows an attacker to craft a malicious file that will be executed from /usr/share/foreman/config/settings.plugins.d/ by foreman-rake on start.
Impact
Indirect Triggering & Privileged RCE: foreman-rake exposes underlying execution primitives that higher-level orchestration tools (like foreman-maintain or foreman-installer) rely on to interact with the application. Because these tools implicitly pass commands down, the vulnerability can be triggered indirectly during routine administrative operations, resulting in Remote Code Execution (RCE) in a high-trust context (often foreman or root).
Total Infrastructure Compromise: Compromising the management plane (Satellite server) allows an attacker to pivot and execute arbitrary code across all Satellite Managed Hosts.
Supply Chain Risk: While direct local exploitation requires prior root access, this flaw presents a critical supply chain risk. An adversary could distribute malicious plugins or compromised configuration files through public repositories (e.g., RubyGems, GitHub). Note: The CVSS vector and severity are based on this supply chain attack vector.
RECOMMENDATIONS
Replace YAML.load with YAML.safeload(content, permittedclasses: [Symbol]) in both locations in settings.rb.
Remove the ERB.new().result evaluation. Configuration files must be treated as static data, never as executable templates.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Remove the ERB.new().result evaluation so configuration files are treated as static data rather than executable Ruby templates.
foreman-rake initialization logic in /usr/share/foreman/config/settings.rb ERB.new(...).result evaluation = removed - Configuration
Replace YAML.load with YAML.safe_load(content, permitted_classes: [Symbol]) in both locations in settings.rb.
foreman-rake configuration loading in /usr/share/foreman/config/settings.rb YAML.load = YAML.safe_load(content, permitted_classes: [Symbol])