Description
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from broken access control in the Foreman component of Red Hat Satellite. An authenticated user with host‑edit privileges can change the match field of an existing lookup value override by altering nested host attributes. The change bypasses the normal authorization logic, enabling the user to retarget a lookup override to a different host. The flaw is classified as CWE‑639, indicating a compromise of authority. The primary impact is the potential unauthorized modification of managed host configurations that span across organizational or location boundaries, which can lead to misconfiguration, service disruption, or policy violations.

Affected Systems

Red Hat Satellite 6 and all of its supported releases from Satellite 6.16 through 6.19 for RHEL 8 and RHEL 9 are affected, including the Satellite capsule, maintenance, and utilities modules for those version ranges.

Risk and Exploitability

Based on the description, it is inferred that exploitation requires an authenticated session with host‑edit permissions, making the attack vector internal – typically from compromised credentials or social engineering. The CVSS score of 6.5 indicates medium severity, and the EPSS score of < 1 % suggests that exploitation attempts are rare. The vulnerability is not listed in the CISA KEV catalog. Because the flaw permits configuration changes across organizational boundaries, it poses a noticeable risk for environments that enforce strict separation between environments, potentially leading to silent misconfiguration and downstream service outages.

Generated by OpenCVE AI on July 21, 2026 at 14:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Red Hat errata patches RHSA-2026:34365 through RHSA-2026:34368 to all affected Satellite releases as soon as they are issued
  • Enforce strict role‑based access control by limiting host‑edit permissions to a minimal set of trusted administrators and regularly reviewing these assignments
  • Enable audit logging for all host lookup override operations and regularly review logs for anomalous activity
  • Consider network segmentation or additional environment isolation to restrict the reach of any unauthorized configuration modifications

Generated by OpenCVE AI on July 21, 2026 at 14:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:satellite:6.17::el9
cpe:/a:redhat:satellite:6.19::el9
cpe:/a:redhat:satellite_capsule:6.17::el9
cpe:/a:redhat:satellite_capsule:6.19::el9
cpe:/a:redhat:satellite_maintenance:6.17::el9
cpe:/a:redhat:satellite_maintenance:6.19::el9
cpe:/a:redhat:satellite_utils:6.17::el9
cpe:/a:redhat:satellite_utils:6.19::el9
References

Wed, 01 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat satellite Capsule
Redhat satellite Maintenance
Redhat satellite Utils
CPEs cpe:/a:redhat:satellite:6.16::el8
cpe:/a:redhat:satellite:6.16::el9
cpe:/a:redhat:satellite:6.18::el9
cpe:/a:redhat:satellite_capsule:6.16::el8
cpe:/a:redhat:satellite_capsule:6.16::el9
cpe:/a:redhat:satellite_capsule:6.18::el9
cpe:/a:redhat:satellite_maintenance:6.16::el8
cpe:/a:redhat:satellite_maintenance:6.16::el9
cpe:/a:redhat:satellite_utils:6.16::el8
cpe:/a:redhat:satellite_utils:6.16::el9
cpe:/a:redhat:satellite_utils:6.18::el9
Vendors & Products Redhat satellite Capsule
Redhat satellite Maintenance
Redhat satellite Utils
References

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
Title Foreman: foreman: unauthorized modification of host configurations via broken access control
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-639
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Redhat Satellite Satellite Capsule Satellite Maintenance Satellite Utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-01T23:53:14.087Z

Reserved: 2026-03-30T10:42:55.307Z

Link: CVE-2026-5135

cve-icon Vulnrichment

Updated: 2026-07-01T14:52:31.307Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T14:30:08Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key