Status: UPDATED
| Advisory ID: CVE-2026-96658
Key Details
| CVE | CVE-2026-96658 |
| CVSS Score / Version | 9.9 (Critical) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | Red Hat Red Hat Satellite 6.16 for RHEL 8, Red Hat Red Hat Satellite 6.16 for RHEL 9, Red Hat Red Hat Satellite 6.17 for RHEL 9, Red Hat Red Hat Satellite 6.18 for RHEL 9, and Red Hat Red Hat Satellite 6.19 for RHEL 9 |
| Classified as | CWE-94 (Improper Control of Generation of Code ('Code Injection')) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References