Where
-Infinity
0

Hi,

Multiple security fixes have been released in Foreman, an open-source lifecycle management tool for physical and virtual servers.

---

CVE-2026-5136: Foreman: Privilege escalation via usergroup role assignment manipulation

The Usergroup model does not validate whether the calling user is permitted to assign the specified roles. A user with createusergroups or editusergroups permission can attach arbitrary roles to a usergroup via the API, add themselves as a member, and inherit elevated privileges.

Affected versions: all Foreman versions CVSS: 8.8 (Important) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Fixed versions: 3.18.2, 3.19.1 Credit: Stanislav Fot (Aisle Research)

References: - Foreman Security: https://theforeman.org/security.html#2026-5136 - Redmine: https://projects.theforeman.org/issues/39478 - Fix: https://github.com/theforeman/foreman/pull/11066

---

CVE-2026-5142: Foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass

The KeyPairsController#show action is excluded from the findcomputeresource callback that enforces taxonomy scoping. An authenticated user with the viewkeypairs permission can download the full PEM private key of any compute resource by database ID, bypassing organization and location boundaries.

Affected versions: all Foreman versions since 1.15.0 CVSS: 6.5 (Moderate) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Fixed versions: 3.18.2, 3.19.1 Credit: Stanislav Fot (Aisle Research)

References: - Foreman Security: https://theforeman.org/security.html#2026-5142 - Redmine: https://projects.theforeman.org/issues/39479 - Fix: https://github.com/theforeman/foreman/pull/11069

---

CVE-2026-5135: Foreman: Unauthorized modification of host configurations via broken access control

When lookup values are submitted as nested attributes during host or hostgroup updates, the match field is permitted and applied without ownership validation. A user with host-edit rights can retarget an existing lookup value override to point at a different host, injecting configuration values into hosts they are not authorized to edit.

Affected versions: all Foreman versions CVSS: 6.5 (Moderate) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Fixed versions: 3.18.2, 3.19.1 Credit: Stanislav Fot (Aisle Research)

References: - Foreman Security: https://theforeman.org/security.html#2026-5135 - Redmine: https://projects.theforeman.org/issues/39480 - Fix: https://github.com/theforeman/foreman/pull/11072

---

CVE-2026-5138: Foreman: Information disclosure via improper validation of nested request parameters

The taxonomyscope controller method loads organization and location IDs from nested request parameters without checking the user's taxonomy membership. An authenticated user with host-edit permissions can supply a foreign organization ID in nested parameters to scope AJAX queries to a tenant they do not belong to, leaking infrastructure metadata such as domains, subnets, and IP availability.

Affected versions: all Foreman versions since 1.7.0 CVSS: 4.3 (Moderate) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Fixed versions: 3.18.2, 3.19.1 Credit: Stanislav Fot (Aisle Research)

References: - Foreman Security: https://theforeman.org/security.html#2026-5138 - Redmine: https://projects.theforeman.org/issues/39481 - Fix: https://github.com/theforeman/foreman/pull/11075

---

Thanks, Ondrej Gajdusek Foreman Release Team

First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.

1 / 2
Source: MITRE
First published (updated )

Hi,

A security vulnerability has been fixed in Foreman, an open-source infrastructure lifecycle management tool.

CVE-2026-1961: Remote Code Execution via command injection in WebSocket proxy

A command injection vulnerability was discovered in Foreman's WebSocket proxy implementation. The vulnerability occurs when constructing shell commands using unsanitized hostname values from compute resource providers (such as VMware vSphere, Libvirt, etc.). An attacker operating a malicious compute resource server can achieve remote code execution on the Foreman server when an administrator accesses VM console functionality through the normal workflow.

Affected versions: Foreman up to and including 3.18.0

CVSS v3.1 Score: 8.0 (High) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Fixed in: Foreman 3.18.1, Foreman 3.17.2, Foreman 3.16.3

Credit: Houssam Sahli

References: - Foreman security page: https://theforeman.org/security.html#2026-1961 - Redmine issue: https://projects.theforeman.org/issues/39121 - GitHub PR: https://github.com/theforeman/foreman/pull/10921

Thanks, Ondrej Gajdusek Foreman Project

Severity
8
Command Injection, OS Command Injection
AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.

1 / 2
Source: MITRE
First published (updated )
Severity
7
Command Injection

Summary: A critical command injection vulnerability exists in Foreman's WebSocket proxy implementation (lib/wsproxy.rb). The vulnerability occurs when constructing shell commands using unsanitized hostname values from compute resource providers. An attacker operating a malicious compute resource server (VMware vSphere, Libvirt, etc.) can achieve remote code execution on the Foreman server when an administrator accesses VM console functionality.

Requirements to exploit: An attacker needs to operate a malicious compute resource server (such as a fake vSphere server) that returns poisoned hostname values. The Foreman administrator must then configure this malicious server as a compute resource and attempt to access the VM console through the normal workflow.

Component affected: foreman

Version affected: Foreman <= 3.17.0 (confirmed), likely all versions from the past 4+ years (wsproxy.rb unchanged since 2020)

Patch available: Yes (need to be reviewed and verified)

Line 44 - Sanitize host parameter safehost = Shellwords.escape(host) Use array form to prevent shell injection cmdarray = [ 'websockify', '--daemon', "--idle-timeout=#{idletimeout}", "--timeout=#{timeout}", port.tos, "#{safehost}:#{hostport}" ] Add SSL options cmdarray += ['--ssl-target'] if ssltarget if Setting[:websocketsencrypt] cmdarray += ['--cert', Setting[:websocketssslcert]] if Setting[:websocketssslcert] cmdarray += ['--key', Setting[:websocketssslkey]] if Setting[:websocketssslkey] end Execute without shell interpretation Open3.popen3(cmdarray) do |stdin, stdout, stderr| # ... existing error handling End Version fixed (if any already): N/A

CVSS: Proposed by reporter - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H (Base Score: 8.8 High)

My understanding of the situation (6.8 Medium/High; Still serious, but not "internet critical" – CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H) Impact (optional): This vulnerability allows remote code execution as the foreman user, providing direct access to Foreman's database credentials and encryption keys. This enables decryption of all stored infrastructure credentials (vCenter, AWS, SSH keys, API tokens), allowing the attacker to pivot and compromise the entire managed infrastructure. Based on Red Hat's classification, this would be considered Critical impact due to the potential for complete infrastructure compromise. Embargo needed: Yes Reason: Given it is command injection Public date: Need to set default 90-days. There is no date received from the reporter.

Acknowledgement: Houssam Sahli

Steps to reproduce if available: 1. Start malicious vSphere server (attacker system): python3 maliciousvsphereserver.py 2. Configure Foreman compute resource (Foreman UI): - Navigate to: Infrastructure → Compute Resources → Create Compute Resource - Provider: VMware - VCenter/Server: <attackerip> (malicious server address) - Username: user - Password: pass - Load Datacenters (it will load EvilDatacenter) - Display Type: VNC - Uncheck "VNC Console Passwords" and "Enable Caching" - Click "Submit" 3. Trigger exploitation: - Navigate to Virtual Machines tab - Locate "TestVM" in the list - Click Actions → Console 4. Verify RCE (Foreman server): find /tmp -name "vsphererce.txt" 2>/dev/null cat /tmp/systemd-private-/tmp/vsphererce.txt Expected output: foreman

First published (updated )
Severity
8
Command Injection, OS Command Injection
AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

A command injection flaw was found in Red Hat Satellite 6.16.5.2 (Foreman 3.12.0.8-1). Although a whitelist for CoreOS Transpiler Command and Fedora CoreOS Transpiler Command is implemented, the whitelist is only enforced on the client-side and is not validated on the server-side. This flaw allows an authenticated user with editsettings permissions to modify these parameters to achieve arbitrary command execution on underlying operating system and bypass safe mode rendering.

1 / 2
Source: Red Hat
First published (updated )
Severity
6.5
AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

1 / 2
Source: MITRE
First published (updated )
Severity
4
XSS

A potential XSS issue within Foreman / Katello has been reported. It is possible to inject JavaScript code into the Description field of a User and save it. This code is then executed when opening certain pages (e.g., Host Collections).

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203