Session Management Flaw in Foreman MCP Server by Red Hat
CVE-2026-12112
7.8HIGH
What is CVE-2026-12112?
A flaw in Foreman MCP Server allows attackers to hijack active administrative sessions without authentication. This occurs due to improper management of authenticated client connections, where a non-secret session ID is trusted without re-validating authentication tokens. As a result, newly created session IDs can be logged, leading to potential privilege escalation and extensive code execution across the infrastructure. Security measures are necessary to mitigate risks associated with session hijacking.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).