https://seclists.org/oss-sec/2026/q3/81: Foman: multiple vulnerabilities fixed in 3.18.2 and 3.19.1 (CVE-2026-5135, CVE-2026-5136, CVE-2026-5138, CVE-2026-5142)
Published Jul 7, 2026
·Updated
Affected Software
2 affected components
Foreman Foreman<3.18.2
Foreman Foreman>3.18.2<=3.19.1
Frequently Asked Questions
1
What is the severity of CVE-2026-5136?
CVE-2026-5136 has been classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2026-5136?
To fix CVE-2026-5136, upgrade to Foreman version 3.19.1 or apply the relevant patches as provided in the security release.
3
What systems are affected by CVE-2026-5136?
CVE-2026-5136 affects all versions of Foreman prior to 3.19.1 that utilize the usergroup role assignment feature.
4
What is the impact of CVE-2026-5136?
The impact of CVE-2026-5136 allows unauthorized users to escalate their privileges through manipulation of usergroup role assignments.
5
Is user intervention required to exploit CVE-2026-5136?
Yes, exploitation of CVE-2026-5136 requires user intervention in the form of an authenticated user manipulating their usergroup role.