Description
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
Published: 2026-10-01
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: SQL injection allowing unauthorized database access
Action: Immediate Patch
AI Analysis

Impact

An SQL injection flaw exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters inside the RegistryProxiesController when handling user-supplied labels from the request path. User input is interpolated directly into raw SQL fragments in methods such as check_blob_push_org_label and get_matching_products_from_org. The vulnerability can lead to unauthorized reading or modification of registry data and potentially enable privilege escalation, since it is exploitable by any user who has the create_personal_access_tokens permission, even without an assigned organization or location.

Affected Systems

The affected systems are Red Hat Satellite 6, including the 6.19 release for RHEL 9. The vulnerability directly impacts the Satellite and its related components such as Satellite Capsule and Satellite Utils as part of the 6.19 update set for EL9.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, and the EPSS score is currently unavailable. The vulnerability is not listed in the CISA KEV catalog. There is no available workaround that meets Red Hat Product Security criteria; the only provided options are considered insufficient. The likely attack vector involves sending crafted HTTP requests to the Registry Proxy endpoint with malicious labels. An attacker only needs the create_personal_access_tokens permission and does not require organizational context, making the exploit readily achievable in the target environment. Given the potential impact on data confidentiality and integrity, organizations should assess the risk quickly and apply the recommended mitigation steps.

Generated by OpenCVE AI on October 1, 2026 at 19:29 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Upgrade Red Hat Satellite to the latest patched version that fixes CVE-2026-56097
  • Revoke the create_personal_access_tokens privilege from users who do not need it to reduce the attack surface
  • Restrict network access to the Katello Registry Proxy endpoint using firewall rules or segmentation to limit exposure

Generated by OpenCVE AI on October 1, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 02 Oct 2026 00:00:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:satellite:6.16::el8
cpe:/a:redhat:satellite:6.16::el9
cpe:/a:redhat:satellite:6.18::el9
cpe:/a:redhat:satellite_capsule:6.16::el8
cpe:/a:redhat:satellite_capsule:6.16::el9
cpe:/a:redhat:satellite_capsule:6.18::el9
cpe:/a:redhat:satellite_utils:6.16::el8
cpe:/a:redhat:satellite_utils:6.16::el9
cpe:/a:redhat:satellite_utils:6.18::el9
References

Thu, 01 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
Title Rubygem-katello: sql injection in registry proxy via labels
First Time appeared Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
Weaknesses CWE-89
CPEs cpe:/a:redhat:satellite:6
cpe:/a:redhat:satellite:6.19::el9
cpe:/a:redhat:satellite_capsule:6.19::el9
cpe:/a:redhat:satellite_utils:6.19::el9
Vendors & Products Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Redhat Satellite Satellite Capsule Satellite Utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T23:42:28.870Z

Reserved: 2026-06-18T19:08:09.850Z

Link: CVE-2026-56097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T18:17:19.597

Modified: 2026-10-02T00:17:02.490

Link: CVE-2026-56097

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-01T12:20:00Z

Links: CVE-2026-56097 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T19:30:11Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')