Description
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
Published: 2026-10-01
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthenticated Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

An authentication bypass flaw exists in Foreman’s host provisioning API. The server checks a provisioning token’s database state rather than its presence in the HTTP request. When a host is actively provisioning and has an unexpired token stored in the database, the valid_host_token? method returns true even if the requester supplies no token. An attacker can therefore access the kickstart template and other provisioning data without authenticating.

Affected Systems

Red Hat Satellite 6 and the 6.19 release for RHEL 9 are affected, as indicated by the CNA vendor product list. These products rely on the Foreman provisioning API endpoint /unattended/provision.

Risk and Exploitability

The CVSS score of 7.5 signals a high severity vulnerability. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an unauthenticated request to the /unattended/provision endpoint while a host is in provisioning. The vulnerability requires the host to be actively provisioning with an unexpired token stored in the database, which may limit its exploitability in some environments.

Generated by OpenCVE AI on October 1, 2026 at 17:45 UTC.

Remediation

Vendor Workaround

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.


OpenCVE Recommended Actions

  • Apply the Red Hat Satellite update RHSA-2026:74503 that fixes host_verifier.rb logic.
  • Restrict access to the /unattended/provision endpoint by enabling network or role‑based access controls if it is not required for automated provisioning.
  • Continuously monitor web server access logs for unauthenticated requests to the /unattended/provision URL and investigate any suspicious activity.

Generated by OpenCVE AI on October 1, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
Title Foreman: unauthenticated information disclosure via provisioning token validation flaw
First Time appeared Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
Weaknesses CWE-306
CPEs cpe:/a:redhat:satellite:6
cpe:/a:redhat:satellite:6.19::el9
cpe:/a:redhat:satellite_capsule:6.19::el9
cpe:/a:redhat:satellite_utils:6.19::el9
Vendors & Products Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Satellite Satellite Capsule Satellite Utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T17:36:27.434Z

Reserved: 2026-06-16T16:57:36.339Z

Link: CVE-2026-12423

cve-icon Vulnrichment

Updated: 2026-10-01T17:36:24.766Z

cve-icon NVD

Status : Received

Published: 2026-10-01T17:17:19.887

Modified: 2026-10-01T18:17:14.853

Link: CVE-2026-12423

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:00:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function