Where
-Infinity
0

oss-secFoman: multiple vulnerabilities fixed in 3.18.2 and 3.19.1 (CVE-2026-5135, CVE-2026-5136, CVE-2026-5138, CVE-2026-5142)

First published (updated )

Foreman Foreman MCP ServerForeman-mcp-server: mcp server: active session hijacking via insecure session state reuse

Risk 69
Severity
7.8
First published (updated )

Foreman foreman-mcp-serverForeman-mcp-server: mcp server: insecure sensitive http header sanitization

Risk 26
Severity
6.2
EPSS
0.15%
First published (updated )

Foreman foreman-mcp-serverDescription The foreman-mcp-server contains two distinct logging mechanisms that expose sensitive se…

Risk 19
Severity
4
First published (updated )

redhat SatelliteForeman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation

Risk 84
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-secCVE-2026-1961: Foman: mote Code Execution via command injection in WebSocket proxy

Foreman ForemanForman: foreman: remote code execution via command injection in websocket proxy

Risk 76
Severity
8
First published (updated )

Foreman ForemanCommand Injection

Risk 33
Severity
7
First published (updated )

Red Hat SatelliteForeman: os command injection via ct_location and fcct_location parameters

Risk 65
Severity
8
First published (updated )

redhat SatelliteForeman: satellite: graphql api permission bypass leads to information disclosure

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Foreman ForemanForeman: foreman: oauth secret exposure via unauthenticated access to the graphql api

Risk 43
Severity
7.5
First published (updated )

Foreman ForemanA flaw was found in foreman before version 3.3. The server exposes a GraphQL API with limited access…

Risk 33
Severity
7
First published (updated )

CVE-2024-7012, CVE-2024-7923: Authentication bypass in Foman & Pulpco

gunicorn gunicornAn authentication bypass vulnerability has been identified in Foreman when deployed with Gunicorn ve…

Risk 72
First published (updated )

Foreman ForemanCommand Injection

Risk 19
Severity
4
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Foreman ForemanXSS

Risk 19
Severity
4
First published (updated )

Red Hat Red Hat SatelliteForeman: host ssh key not being checked in remote execution

Risk 38
Severity
6.8
EPSS
0.04%
First published (updated )

Puppet CandlepinIn puppet-candlepin shipped with the foreman-installer rpm, when calling /usr/share/candlepin/cpdb w…

Risk 5
Severity
1
First published (updated )

Foreman Datacenter pluginA password leak was identified on Foreman project which will expose password in plaintext through Fo…

Risk 18
Severity
4
First published (updated )

CVE-2016-7078: Foreman user with no organizations or locations can see all resources A user account…

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Foreman ForemanIt was reported that non-admin users with the view_hosts permission containing a filter are able to …

Risk 5
Severity
1
First published (updated )

Foreman Foremanlarry campbell reports via the foreman bug tracker: This was found on Foreman 1.9.0: I came across…

Risk 18
Severity
4
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203