Description
A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.
Published: 2026-10-07
Score: 5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

When publishing a distribution tree, Pulp-rpm uses addon and variant IDs from the .treeinfo file as directory names. If an attacker crafts these IDs, the publish process can create a new directory outside the intended task work area and write repository metadata and packages there as the Pulp worker user. Existing files or directories are not overwritten, yet the flaw allows the creation of arbitrary files in privileged locations, which could be used to store malicious content or alter critical data. The vulnerability does not disclose data or stop the service, but it permits unauthorized file creation under elevated privileges.

Affected Systems

The flaw affects Red Hat Satellite 6, Red Hat Update Infrastructure 4 for Cloud Providers, and Red Hat Update Infrastructure 5. No specific version ranges are listed, but any deployment of these products that uses pulp-rpm for distribution tree publishing is potentially impacted.

Risk and Exploitability

The CVSS score of 5 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation. Attacks would require an actor with the ability to sync or upload a distribution tree to the system—typically a user with authorized repository management permissions. The likelihood of exploitation depends on the presence of such permissions and the usage of untrusted upstream sources. The official workaround states that syncing from trusted upstreams avoids a crafted .treeinfo file, but an account that can upload a tree directly can still supply the file. Until a patched version is released, the risk remains for administrators who grant sync or upload rights to users that are not fully trusted.

Generated by OpenCVE AI on October 7, 2026 at 07:33 UTC.

Remediation

Vendor Workaround

Syncing distribution trees only from a trusted upstream avoids a crafted .treeinfo from that source. An account that can upload a tree directly can still supply the file. Otherwise, Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.


OpenCVE Recommended Actions

  • Apply the latest Red Hat security updates for Red Hat Satellite and Red Hat Update Infrastructure when they become available.
  • Restrict sync and upload permissions to trusted administrators only.
  • Configure distribution tree synchronization to use only trusted upstream sources and avoid local uploads of .treeinfo files.
  • Monitor the system for unauthorized directory creation outside the intended task areas.

Generated by OpenCVE AI on October 7, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 07 Oct 2026 06:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in pulp-rpm when it publishes a distribution tree. Addon and variant ids from .treeinfo are used as directory names. A user who can sync or upload that tree can make the publish task create a new directory outside the task work area and write that tree's repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service.
Title Pulp-rpm: distribution tree publish creates directories from .treeinfo ids
First Time appeared Redhat
Redhat rhui
Redhat satellite
Weaknesses CWE-22
CPEs cpe:/a:redhat:rhui:4::el8
cpe:/a:redhat:rhui:5::el9
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat rhui
Redhat satellite
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T06:14:50.047Z

Reserved: 2026-10-01T11:51:10.972Z

Link: CVE-2026-103870

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T06:16:35.373

Modified: 2026-10-07T14:47:21.140

Link: CVE-2026-103870

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-07T05:34:30Z

Links: CVE-2026-103870 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T07:45:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')