Description
A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries.
Published: 2026-10-08
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Disclosure of Repository Metadata
Action: Assess Impact
AI Analysis

Impact

The vulnerability originates in the Katello Docker Tags repositories API, which fails to enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization can supply a tag identifier belonging to another organization and retrieve repository metadata associated with that tag. This allows unauthorized disclosure of repository configuration information across organization boundaries.

Affected Systems

The affected systems are Red Hat products that integrate Katello, notably Red Hat Satellite 6 and Red Hat Hardened Images. Any instance running Katello code that implements the Docker Tags repositories API is potentially impacted; the advisory does not list specific version numbers, so all current releases that include the vulnerable code could be affected.

Risk and Exploitability

The CVSS base score of 4.3 indicates a low severity level. Because no EPSS score is available and the vulnerability is not catalogued in the CISA KEV list, there is no evidence of active exploitation. An attacker would need authenticated access with product‑view permissions in one organization and the tag identifier of a resource in another organization, implying the attack path requires legitimate API calls from a credentialed user. Consequently, the primary risk stems from over‑permissive user roles rather than a publicly exploitable flaw.

Generated by OpenCVE AI on October 8, 2026 at 06:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Red Hat errata for Satellite 6 that contains the Katello organization‑scoping fix.
  • Restrict product‑view permissions so that users only have access to organizations they belong to; remove any unnecessary cross‑organization privileges.
  • Enable and monitor Katello API audit logs to detect and investigate cross‑organization repository access.

Generated by OpenCVE AI on October 8, 2026 at 06:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries.
Title Rubygem-katello: katello docker tags repositories api cross-organization authorization bypass
First Time appeared Redhat
Redhat hummingbird
Redhat satellite
Weaknesses CWE-639
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat hummingbird
Redhat satellite
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Redhat Hummingbird Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T03:41:31.998Z

Reserved: 2026-10-08T03:29:12.521Z

Link: CVE-2026-107444

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:14.237

Modified: 2026-10-08T04:17:14.237

Link: CVE-2026-107444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key