Impact
The vulnerability resides in Foreman’s Usergroup model, which fails to confirm that a calling user has the authority to assign roles to a user group. An authenticated user who can manage user groups can attach any role—including administrative roles—to a group and then enroll themselves as a member. By doing so, the attacker effectively scales their own privileges to full administrator control over the system. This vulnerability represents a CWE‑266: Least Privilege flaw, as the system accepts privilege escalation without proper validation.
Affected Systems
Red Hat Satellite 6 and all related components—Satellite Capsule, Satellite Maintenance, and Satellite Utils—across multiple releases are impacted. This includes the base Satellite 6 for RHEL 8 and RHEL 9, Satellite 6.16 for both RHEL 8 and RHEL 9, as well as Satellite 6.17 through 6.19 on RHEL 9, along with the corresponding Capsule, Maintenance, and Utils builds.
Risk and Exploitability
The CVSS score of 8.8 classifies this flaw as high severity. An EPSS score of less than 1% indicates a low probability of exploitation; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an authenticated session with usergroup‑management rights, which a compromised or privileged user can readily obtain, enabling rapid escalation to administrator level with minimal effort.
OpenCVE Enrichment