Impact
This vulnerability arises from broken access control in the Foreman component of Red Hat Satellite. An authenticated user with host‑edit privileges can change the match field of an existing lookup value override by altering nested host attributes. The change bypasses the normal authorization logic, enabling the user to retarget a lookup override to a different host. The flaw is classified as CWE‑639, indicating a compromise of authority. The primary impact is the potential unauthorized modification of managed host configurations that span across organizational or location boundaries, which can lead to misconfiguration, service disruption, or policy violations.
Affected Systems
Red Hat Satellite 6 and all of its supported releases from Satellite 6.16 through 6.19 for RHEL 8 and RHEL 9 are affected, including the Satellite capsule, maintenance, and utilities modules for those version ranges.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires an authenticated session with host‑edit permissions, making the attack vector internal – typically from compromised credentials or social engineering. The CVSS score of 6.5 indicates medium severity, and the EPSS score of < 1 % suggests that exploitation attempts are rare. The vulnerability is not listed in the CISA KEV catalog. Because the flaw permits configuration changes across organizational boundaries, it poses a noticeable risk for environments that enforce strict separation between environments, potentially leading to silent misconfiguration and downstream service outages.
OpenCVE Enrichment