Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-12541

Опубликовано: 01 окт. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Отчет

Successful exploitation of this issue allows a restricted user to escalate privileges to the foreman account and execute arbitrary commands. This grants control over the Satellite database and configurations, enabling lateral movement and full root remote code execution on all managed hosts.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6satellite:el8/foremanAffected
Red Hat Satellite 6.16 for RHEL 8foremanFixedRHSA-2026:7450601.10.2026
Red Hat Satellite 6.16 for RHEL 9foremanFixedRHSA-2026:7450601.10.2026
Red Hat Satellite 6.18 for RHEL 9foremanFixedRHSA-2026:7450401.10.2026
Red Hat Satellite 6.19 for RHEL 9foremanFixedRHSA-2026:7450301.10.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2489970foreman: command injection in foreman-rake database tasks

EPSS

Процентиль: 69%
0.01303
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
2 дня назад

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

CVSS3: 8.2
debian
2 дня назад

A flaw was found in Foreman. OS command injection vulnerabilities exis ...

CVSS3: 8.2
github
2 дня назад

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

EPSS

Процентиль: 69%
0.01303
Низкий

8.2 High

CVSS3