https://seclists.org/oss-sec/2026/q1/396: CVE-2026-1961: Foman: mote Code Execution via command injection in WebSocket proxy
Published Mar 27, 2026
·Updated
Affected Software
1 affected component
Foreman Foreman<=3.18.0
CVE-2026-1961 is categorized as a critical vulnerability since it allows remote code execution.
To fix CVE-2026-1961, update your Foreman installation to the latest version where the vulnerability is patched.
CVE-2026-1961 enables attackers to execute arbitrary commands on the server through the WebSocket proxy.
CVE-2026-1961 affects multiple versions of Foreman prior to the latest security update.
Using an outdated version of Foreman that is vulnerable to CVE-2026-1961 poses significant security risks.