Common Vulnerabilities and Exposures (CVE)

CVE-2026-79654

Oct 1, 2026 23:42:38 UTC

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may ...

CVE-2026-56098

Oct 1, 2026 23:42:30 UTC

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized re...

CVE-2026-56097

Oct 1, 2026 23:42:28 UTC

A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. Th...

CVE-2026-12545

Oct 1, 2026 23:42:25 UTC

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into ...

CVE-2026-12542

Oct 1, 2026 23:42:23 UTC

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then execut...

CVE-2026-14164

Oct 1, 2026 23:41:36 UTC

A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent process...

CVE-2026-58015

Oct 1, 2026 23:41:29 UTC

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_conte...

CVE-2026-58014

Oct 1, 2026 23:41:27 UTC

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial ...

CVE-2026-86345

Oct 1, 2026 23:27:47 UTC

A flaw was found in 389-ds-base. The server does not discard plaintext bytes already buffered from a client connection when negotiating StartTLS, allowing an on-path attacker to inject a crafted LDAP message that is processed after the TLS ...

CVE-2026-96659

Oct 1, 2026 23:26:21 UTC

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the ...

CVE-2026-12544

Oct 1, 2026 23:26:00 UTC

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a mult...

CVE-2026-12541

Oct 1, 2026 23:25:54 UTC

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and t...

CVE-2026-12540

Oct 1, 2026 23:25:51 UTC

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. Whil...

CVE-2026-12423

Oct 1, 2026 23:25:49 UTC

A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning ...

CVE-2026-12405

Oct 1, 2026 23:25:44 UTC

A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the appl...