Description
A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials.
Published: 2026-10-08
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Authorization bypass allowing cross-organization repository access
Action: Assess Impact
AI Analysis

Impact

The Flatpak Remote Repositories API in Katello does not properly enforce authorization when an authenticated user retrieves a flatpak remote repository by its identifier. A user with view permission in one organization may be able to read repository information from another organization and may invoke the mirror action to create a repository in a product the user can edit. The consequences include unintended disclosure of repository details and the potential to configure a product with a remote URL and credentials from another organization, which may lead to further unauthorized changes or data leakage.

Affected Systems

The vulnerability affects Katello, which is part of Red Hat Hardened Images and Red Hat Satellite 6. Specific impacted versions are not listed in the advisory, so any deployment using a Katello instance before a patch may be vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact. EPSS information is unavailable and the issue is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited. The attack requires an authenticated user with flatpak remote view permission and is likely performed via the exposed API over the network. While the exploit risk is moderate, the cross‑organization reach makes it a noteworthy concern for environments with multiple orgs accessing shared resources.

Generated by OpenCVE AI on October 8, 2026 at 05:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch as soon as it is available.
  • Restrict flatpak remote view permissions to only trusted users and enforce least‑privilege access controls.
  • Audit cross‑organization repository access logs for unusual activity and review organization memberships.
  • If a patch is not yet available, isolate flatpak remote repositories to dedicated organizations and remove any unnecessary cross‑organization permissions.

Generated by OpenCVE AI on October 8, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 04:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials.
Title Rubygem-katello: katello flatpak remote repositories api cross-organization authorization bypass
First Time appeared Redhat
Redhat hummingbird
Redhat satellite
Weaknesses CWE-639
CPEs cpe:/a:redhat:hummingbird:1
cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat hummingbird
Redhat satellite
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Redhat Hummingbird Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-08T03:43:03.553Z

Reserved: 2026-10-08T03:29:15.423Z

Link: CVE-2026-107445

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T04:17:19.220

Modified: 2026-10-08T04:17:19.220

Link: CVE-2026-107445

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:00:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key