Description
A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is restricted by a permission filter can enumerate job invocation IDs and read the live output, rendered script, and input values for other users' job invocations within their own organizations.
Published: 2026-09-17
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Apply patch
AI Analysis

Impact

A flaw in the foreman_remote_execution plugin bypasses the view_job_invocations permission check during the show_template_invocation_by_host action, allowing an authenticated user to resolve any job invocation ID and read its live output, rendered script, and input values even when their visibility is normally restricted. This omission permits unauthorized disclosure of potentially sensitive job execution data within the user's organization. The vulnerability is a classic case of missing authorization (CWE-863), resulting in a breach of confidentiality rather than a denial of service or code execution.

Affected Systems

The affected product is Red Hat Satellite 6, specifically the foreman_remote_execution plugin. No specific affected version is listed; the issue applies to all builds that have not yet been patched by Red Hat’s security update for this CVE.

Risk and Exploitability

The CVSS base score of 4.3 indicates a moderate threat severity. EPSS is not available, so the likelihood of exploitation is unclear, and the vulnerability is not currently listed in the CISA KEV catalog. A legitimate user with an account that has limited job invocation visibility can enumerate IDs and read other users’ job data, so the attack vector is an authenticated user within the same organization. Given the absence of a known workaround, the risk stems from insufficient access control rather than from any technical complexity or exploit code that is readily available.

Generated by OpenCVE AI on September 17, 2026 at 22:19 UTC.

Remediation

Vendor Workaround

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.


OpenCVE Recommended Actions

  • Install the security update for Red Hat Satellite 6 that contains the fix for CVE-2026-92904.
  • Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
  • After patching, audit and apply least-pri­vilege policies so that only users with explicit view_job_invocations permission can access job invocation data.
  • If the patch is not yet available, limit exposure by disabling the foreman_remote_execution plugin for non-trusted users or reducing its usage to essential personnel while monitoring logs for unusual job invocation enumeration.

Generated by OpenCVE AI on September 17, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Red Hat
Red Hat red Hat Satellite 6
Vendors & Products Red Hat
Red Hat red Hat Satellite 6

Thu, 17 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is restricted by a permission filter can enumerate job invocation IDs and read the live output, rendered script, and input values for other users' job invocations within their own organizations.
Title Rubygem-foreman_remote_execution: job output readable without object-level view_job_invocations check
First Time appeared Redhat
Redhat satellite
Weaknesses CWE-863
CPEs cpe:/a:redhat:satellite:6
Vendors & Products Redhat
Redhat satellite
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Red Hat Red Hat Satellite 6
Redhat Satellite
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-17T14:47:25.790Z

Reserved: 2026-09-17T10:59:41.932Z

Link: CVE-2026-92904

cve-icon Vulnrichment

Updated: 2026-09-17T14:44:00.690Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T13:17:00.877

Modified: 2026-09-18T19:06:08.407

Link: CVE-2026-92904

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-92904 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T22:30:17Z

Weaknesses