REDHAT-BUG-2524899: Medium severity the Foreman Project Foreman vulnerability

Published Aug 27, 2026
·
Updated

The reported issue is a valid object-level authorization bypass in Foreman's template revision handling.

TemplatesController#revision (app/controllers/templatescontroller.rb) loads the requested audit with Audit.find(params[:version]). The corresponding API controllers use Audit.authorized(:viewauditlogs).find(params[:version]). The UI action is a collection endpoint and is not subject to findresource, so authorization checks only whether the user may invoke the action (for example viewptables). It does not authorize the specific audit object supplied by the user.

An authenticated, low-privileged user with a template permission such as viewptables, scoped to one organization or location, can therefore retrieve a historical template revision from another organization or location by supplying its audit identifier. This is possible without viewauditlogs and without access to the template through the normal template API. The same revision action is inherited by partition table, provisioning template, report template, and remote execution job template controllers.

The exposed data is the historical template content, which may include sensitive configuration, credentials, or other secrets depending on customer configuration. This unrestricted lookup has been present since the introduction of STI templates.

Affected Software

1 affected component
the Foreman Project Foreman

Event History

Aug 27, 2026
Data Sourced
via Red Hat·09:58 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated low-privileged user who has a template-related permission, such as view_ptables, scoped to any organization or location can exploit it. The user does not need view_audit_logs or normal API access to the target template.

2

What does an attacker need to retrieve another scope's revision?

The attacker needs to supply the identifier of the target audit record to the revision action. Authorization verifies that the user may invoke the action, but does not authorize access to that specific audit object.

3

Which template types are affected?

The inherited revision action affects partition table, provisioning template, report template, and remote execution job template controllers, in addition to template revision handling.

4

What information could be exposed?

Historical template content from another organization or location may be disclosed. That content can include sensitive configuration, credentials, or other sensitive data stored in template revisions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203