REDHAT-BUG-2452971: Medium severity the Foreman Project Foreman vulnerability

Published Mar 30, 2026
·
Updated

Summary: A cross-tenant information disclosure flaw was found in Foreman. The taxonomyscope controller method does not validate organization and location IDs from nested request parameters against the current user's taxonomy memberships, bypassing the existing settaxonomy authorization check. This flaw allows an authenticated user with host-edit permissions to leak infrastructure metadata such as subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs from organizations and locations they do not belong to.

Requirements to exploit: Authenticated Foreman account with createhosts or edithosts permission (or equivalent hostgroup permissions) in at least one organization. Attacker crafts a single HTTP request with a valid own-org ID at the top level and a foreign org ID in nested params.

Affected Software

1 affected component
the Foreman Project Foreman

Event History

Mar 30, 2026
Data Sourced
via Red Hat·10:53 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2452971?

The severity of REDHAT-BUG-2452971 is medium, rated at 4.

2

What is REDHAT-BUG-2452971 about?

REDHAT-BUG-2452971 describes a cross-tenant information disclosure flaw in Foreman due to inadequate validation of organization and location IDs.

3

How can I mitigate the risks of REDHAT-BUG-2452971?

To mitigate the risks of REDHAT-BUG-2452971, ensure that proper authorization checks are implemented for the taxonomy_scope method.

4

Which software is affected by REDHAT-BUG-2452971?

The affected software for REDHAT-BUG-2452971 is the Foreman Project Foreman.

5

When was REDHAT-BUG-2452971 published?

REDHAT-BUG-2452971 was published on March 30, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203