Description
Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Integrity compromise via job status manipulation
Action: Patch when available
AI Analysis

Impact

A missing authentication check in the smart_proxy_dynflow task callbacks allows an attacker to submit a job completion report without providing the required one‑time token. The vulnerability can be abused to mark a running remote execution job as succeeded or failed, thereby altering the recorded job outcome. This flaw is rooted in CWE‑306, improper authorization.

Affected Systems

The flaw affects Red Hat Satellite 6, specifically the smart_proxy_dynflow component. No specific sub‑versions are listed, so all currently installed instances of Satellite 6 are assumed vulnerable.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting that widespread exploitation is not yet confirmed. Attackers would need to know the identifier of a running job and be able to reach the callback endpoint over the network. Once these prerequisites are satisfied, they can send crafted HTTP requests to change job status. The risk is therefore moderate with potential impact on the integrity of job reporting and downstream automation that relies on accurate job outcomes.

Generated by OpenCVE AI on October 7, 2026 at 14:56 UTC.

Remediation

Vendor Workaround

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.


OpenCVE Recommended Actions

  • Apply the Red Hat Satellite 6 security update that fixes the smart_proxy_dynflow authentication issue as soon as it becomes available.
  • If the update is unavailable, limit network access to the smart_proxy_dynflow callback interfaces (e.g., via firewall or ACLs) so that only trusted hosts can communicate, thereby preventing unauthenticated requests.
  • Configure monitoring and alerting for unexpected job status changes so anomalous updates can be detected and investigated promptly.

Generated by OpenCVE AI on October 7, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Satellite 6
Vendors & Products Red Hat
Red Hat red Hat Satellite 6

Wed, 07 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result.
Title Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-306
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Red Hat Red Hat Satellite 6
Redhat Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-07T12:36:29.932Z

Reserved: 2026-10-07T10:19:09.047Z

Link: CVE-2026-107151

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-07T13:17:19.783

Modified: 2026-10-07T14:47:21.140

Link: CVE-2026-107151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T16:30:17Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function