CVE-2026-56098: Rubygem-katello: improper authorization logic allows resource enumeration

Published Jun 18, 2026
·
Updated

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registryauthorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.

Other sources

Description

The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registryauthorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement).

This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.

--------------------------------------------------------------------------------

$ cat /usr/share/gems/gems/katello-4.20.0.rc1/app/controllers/katello/api/registry/registryproxiescontroller.rb

def registryauthorize

@repository = findreadablerepository

return true if ['GET', 'HEAD'].include?(request.method) && @repository && !requireuserauthorization?

return true if authenticatefromrequest(request.headers['Authorization'])

unauthorized [should be: “unauthorized and return”]

end

def unauthorized

redirectauthorizationheaders

rendererror('unauthorized', :status => :unauthorized)

false [no return here neither]

end

--------------------------------------------------------------------------------

Impact

User Enumeration: Attackers can verify the existence of usernames. Invalid users cause a server-side crash (500 Internal Server Error) because the fall-through logic cannot handle a null user object. Valid users trigger a semantic error (404 NAMEUNKNOWN), confirming their presence.

Resource Mapping: Unauthorized users can map hidden organizational structures. By observing the discrepancy between "Organization not found" and "Product not found", an attacker can confirm the existence of Organizations and Products they are explicitly forbidden from viewing.

Exploit Chain Enabler: This vulnerability provides the necessary "transport" for the F-38 SQL Injection in Registry Proxy via labels, allowing malicious payloads to reach the database layer despite failing initial authorization checks.

RECOMMENDATIONS

Fix Control Flow: Add an explicit “and return” to the unauthorized method call within registryauthorize to ensure the filter chain terminates immediately and prevents execution fall-through.

Normalize Error Responses: Configure the Registry API to return a uniform 401 Unauthorized response for all failed authorization attempts to eliminate the enumeration oracle.

— Red Hat

Affected Software

1 affected component
rubygem/katello<4.21.2, <5.0.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rubygem-katello to a version that resolves this vulnerability.

    Fixed in 4.21.2
  2. Upgrade

    Upgrade rubygem-katello to a version that resolves this vulnerability.

    Fixed in 5.0.1
  3. Configuration

    Configure the Registry API to return a uniform 401 Unauthorized response for all failed authorization attempts.

    Katello Registry API failed authorization response = 401 Unauthorized

Event History

Jun 18, 2026
Data Sourced
via Red Hat·06:57 PM
DescriptionSeverityAffected Software
Oct 1, 2026
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An unprivileged attacker with low-level privileges can exploit it remotely. No user interaction is required.

2

What information can be exposed?

Differential responses can allow enumeration of valid Users, Organizations, and Products across the entire instance. The provided impact data indicates low confidentiality impact, with no integrity or availability impact.

3

What is required for exploitation?

The vulnerable authorization path must be reachable in Katello's RegistryProxiesController. Exploitation relies on the authorization filter continuing execution after it identifies an unauthorized request, and is rated low complexity.

4

Are fixes or advisories available?

The provided references list Red Hat advisories RHSA-2026:74503, RHSA-2026:74504, and RHSA-2026:74506. The supplied data does not identify the affected or fixed package versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203