No analysis available yet.
Vendor Workaround
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:satellite:6 |
Thu, 01 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk. | |
| Title | Foreman: ssti and insecure deserialization in foreman-rake configuration | |
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:/a:redhat:satellite:6.19::el9 cpe:/a:redhat:satellite_capsule:6.19::el9 cpe:/a:redhat:satellite_utils:6.19::el9 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-01T16:59:38.446Z
Reserved: 2026-06-17T17:42:09.510Z
Link: CVE-2026-12544
No data.
Status : Received
Published: 2026-10-01T17:17:20.340
Modified: 2026-10-01T17:17:20.340
Link: CVE-2026-12544
No data.
OpenCVE Enrichment
No data.
-
CWE-502
Deserialization of Untrusted Data