← All Advisories

CVE-2026-96659

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-96659

Key Details

CVECVE-2026-96659
CVSS Score / Version9.1 (Critical) / CVSS v3.1
Updated2026-10-02
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
CVSS Proseattack vector is network; attack complexity is low; privileges required is low; user interaction is none; scope is changed; confidentiality impact is high; integrity impact is low; availability impact is low.
Affected productsRed Hat Red Hat Satellite 6.16 for RHEL 8, Red Hat Red Hat Satellite 6.16 for RHEL 9, Red Hat Red Hat Satellite 6.17 for RHEL 9, Red Hat Red Hat Satellite 6.18 for RHEL 9, and Red Hat Red Hat Satellite 6.19 for RHEL 9
Classified asCWE-267 (Privilege Defined With Unsafe Actions)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatRed Hat Satellite 6.16 for RHEL 8
Red HatRed Hat Satellite 6.16 for RHEL 9
Red HatRed Hat Satellite 6.17 for RHEL 9
Red HatRed Hat Satellite 6.18 for RHEL 9
Red HatRed Hat Satellite 6.19 for RHEL 9
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account. (NVD)

What to Do

Monitor Red Hat's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-96659
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-96659