Authorization Flaw in Foreman's GraphQL API Affects Red Hat
CVE-2025-9572
5MEDIUM
Key Information:
- Vendor
The Foreman
- Status
- Vendor
- CVE Published:
- 27 February 2026
What is CVE-2025-9572?
An authorization flaw in Foreman's GraphQL API presents a significant concern for users, enabling low-privileged users to gain access to sensitive metadata beyond their assigned permissions. Unlike the REST API, which enforces proper access controls, the GraphQL endpoint lacks sufficient filtering measures. This oversight allows unauthorized information retrieval, potentially leading to data leakage and security compliance issues.
Affected Version(s)
Foreman 1.22.0 < 3.16.2
Red Hat Satellite 6.15 for RHEL 8 0:3.9.1.14-1.el8sat
Red Hat Satellite 6.15 for RHEL 8 0:6.15.5.7-1.el8sat
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Ohad Levy (Redhat) for reporting this issue.
