CVE-2026-13316: Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config
Published Jun 18, 2026
·Updated
A flaw has been found in foreman when HTTP parameters are modified in httpproxiescontroller and httpproxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Affected Software
3 affected components
foreman
redhat Satellite>=6.0<=6.19
theforeman foreman
Event History
Jun 18, 2026
Data Sourced
via Red Hat·03:07 PM
DescriptionSeverityAffected Software
Jun 30, 2026
CVE Published
via MITRE·09:53 AM
Data Sourced
via MITRE·09:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-13316?
CVE-2026-13316 has a medium severity rating of 4.4.
2
How does CVE-2026-13316 affect Foreman?
CVE-2026-13316 allows attackers to perform SSRF attacks and access cloud metadata services.
3
What are the potential impacts of CVE-2026-13316?
Exploitation of CVE-2026-13316 can lead to unauthorized access to sensitive cloud metadata.
4
How do I fix CVE-2026-13316?
To mitigate CVE-2026-13316, ensure that HTTP parameters are properly validated in Foreman configuration.
5
Which environments are affected by CVE-2026-13316?
CVE-2026-13316 affects cloud environments including AWS, GCP, and Azure.