Description
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Published: 2026-07-01
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in Foreman. Authenticated users who possess the 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH keys belonging to other tenants by supplying a key‑pair identifier. This control flaw, a CWE‑639 information‑disclosure by‑tenant exposure of confidential credentials.

Affected Systems

Red Hat Satellite 6, including the base release and the 6.16 release for RHEL 8 and for RHEL 9, plus the 6.17, 6.18, and 6.19 releases for RHEL 9, is affected. Satellite Capsule, Satellite Maintenance, and Satellite Utils components for the corresponding version numbers are also impacted. Any installation of these specific product versions remains vulnerable until an update that addresses the issue is applied.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as medium severity. Exploitation requires an authenticated account with the view_keypairs permission, limiting the attack surface to privileged or compromised users. The EPSS score of < 1% and absence from the CISA KEV catalog indicate a low likelihood of widespread exploitation. Nonetheless, once the required permissions are present, an attacker can retrieve any private SSH key by providing its identifier, resulting in immediate confidentiality loss across tenant boundaries.

Generated by OpenCVE AI on July 22, 2026 at 14:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Red Hat Satellite update shipped in RHSA-2026:34367 or RHSA-2026:34368.
  • Restrict or remove the view_keypairs permission for users who do not require access to SSH key pairs.
  • Enable logging of key‑pair download activity.

Generated by OpenCVE AI on July 22, 2026 at 14:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:satellite:6.17::el9
cpe:/a:redhat:satellite:6.19::el9
cpe:/a:redhat:satellite_capsule:6.17::el9
cpe:/a:redhat:satellite_capsule:6.19::el9
cpe:/a:redhat:satellite_maintenance:6.17::el9
cpe:/a:redhat:satellite_maintenance:6.19::el9
cpe:/a:redhat:satellite_utils:6.17::el9
cpe:/a:redhat:satellite_utils:6.19::el9
References

Wed, 01 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Redhat satellite Capsule
Redhat satellite Maintenance
Redhat satellite Utils
CPEs cpe:/a:redhat:satellite:6.16::el8
cpe:/a:redhat:satellite:6.16::el9
cpe:/a:redhat:satellite:6.18::el9
cpe:/a:redhat:satellite_capsule:6.16::el8
cpe:/a:redhat:satellite_capsule:6.16::el9
cpe:/a:redhat:satellite_capsule:6.18::el9
cpe:/a:redhat:satellite_maintenance:6.16::el8
cpe:/a:redhat:satellite_maintenance:6.16::el9
cpe:/a:redhat:satellite_utils:6.16::el8
cpe:/a:redhat:satellite_utils:6.16::el9
cpe:/a:redhat:satellite_utils:6.18::el9
Vendors & Products Redhat satellite Capsule
Redhat satellite Maintenance
Redhat satellite Utils
References

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Title Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-639
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Satellite Satellite Capsule Satellite Maintenance Satellite Utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-01T23:53:16.614Z

Reserved: 2026-03-30T12:08:56.764Z

Link: CVE-2026-5142

cve-icon Vulnrichment

Updated: 2026-07-01T15:01:15.365Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:30:17Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key