Impact
The foreman_ansible plugin’s Ansible override values API contains a flaw in its destroy operation: it resolves the target LookupValue by its numeric ID without verifying that the caller is authorized to edit the associated AnsibleVariable. An authenticated user holding the edit_ansible_variables permission can therefore delete any LookupValue by ID, including values that belong to Ansible variables outside their permission scope and to Puppet smart class parameters. This arbitrary deletion can corrupt configuration management, break automation jobs, or cause service interruption.
Affected Systems
Affects Red Hat Satellite 6 installations that use the foreman_ansible plugin. No specific minor version is listed, so all current releases of Satellite 6 are considered vulnerable until an official fix is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity risk. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation activity has not been observed to date. The attack requires authentication and the edit_ansible_variables permission; once the attacker can send a lookup-value ID to the destroy endpoint, the system removes the target record without permission validation. Because the endpoint lacks scope checks, the deletion can span across different model objects, potentially affecting any override data the user has indirect access to. No additional privilege escalation is needed beyond the existing role assignment.
OpenCVE Enrichment