Description
A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.
Published: 2026-08-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass
Action: Apply patch
AI Analysis

Impact

The vulnerability resides in the Katello component of Red Hat Satellite 6. The Content View Filter Rules API fails to enforce authorization on the parent Content View Filter. An authenticated user with limited privileges in one organization can supply the identifier of a filter in another organization and read or alter its rules, leading to unauthorized disclosure of filter‑rule data and unauthorized changes to unpublished filter configuration, effectively breaching confidentiality and integrity boundaries across tenants. The weakness is an authorization bypass (CWE‑639).

Affected Systems

Red Hat Satellite 6 is affected. No specific version range is provided in the advisory; the issue applies to all instances that use the Katello content view filter rules API. The vulnerability is relevant to customers running any organization setup within Satellite 6 that rely on cross‑organization content view filtering.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk. Without an EPSS score, the probability of exploitation cannot be quantified, but the vulnerability is known to exist in a product in production environments. Because the flaw is limited to users with existing content‑view permissions, it does not grant full administrative control, reducing the potential impact compared to high‑privilege exploits. Nonetheless, the ability to read and modify filter rules across tenant boundaries could significantly affect organizational data separation and control. The vulnerability is not listed in the CISA KEV catalog, so no publicly confirmed exploit is documented.

Generated by OpenCVE AI on August 27, 2026 at 14:53 UTC.

Remediation

Vendor Workaround

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.


OpenCVE Recommended Actions

  • Apply the official Red Hat security update for Satellite 6 to enforce proper authorization on the Content View Filter Rules API.
  • Restrict or remove Content View permissions for users who do not require cross‑organization access, ensuring least‑privilege principles are followed.
  • Audit filter rule activity and review any cross‑organization changes to detect potential abuse.

Generated by OpenCVE AI on August 27, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 27 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Satellite 6
Vendors & Products Red Hat
Red Hat red Hat Satellite 6

Thu, 27 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the parent Content View Filter. An authenticated, low-privileged user with Content View permissions in one organization may be able to access and modify filter rules belonging to a Content View Filter in another organization by supplying that filter's identifier. This can result in unauthorized disclosure of filter-rule information and unauthorized changes to unpublished Content View filter configuration.
Title Rubygem-katello: cross-tenant content view filter rule access and modification via unauthorized parent filter lookup
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-639
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Red Hat Red Hat Satellite 6
Redhat Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-27T14:30:55.692Z

Reserved: 2026-08-27T10:42:56.761Z

Link: CVE-2026-81668

cve-icon Vulnrichment

Updated: 2026-08-27T14:27:32.308Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-27T13:18:42.463

Modified: 2026-08-28T21:17:10.720

Link: CVE-2026-81668

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-27T00:00:00Z

Links: CVE-2026-81668 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T15:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key