Status: UPDATED
| Advisory ID: CVE-2026-96659
Key Details
| CVE | CVE-2026-96659 |
| CVSS Score / Version | 9.1 (Critical) / CVSS v3.1 |
| Updated | 2026-10-02 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is low. |
| Affected products | Red Hat Red Hat Satellite 6.16 for RHEL 8, Red Hat Red Hat Satellite 6.16 for RHEL 9, Red Hat Red Hat Satellite 6.17 for RHEL 9, Red Hat Red Hat Satellite 6.18 for RHEL 9, and Red Hat Red Hat Satellite 6.19 for RHEL 9 |
| Classified as | CWE-267 (Privilege Defined With Unsafe Actions) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account. (NVD)
What to Do
Monitor Red Hat's web page for any future patch releases.
References