Session Management Flaw in Foreman MCP Server by Red Hat
CVE-2026-12112

7.8HIGH

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
23 June 2026

What is CVE-2026-12112?

A flaw in Foreman MCP Server allows attackers to hijack active administrative sessions without authentication. This occurs due to improper management of authenticated client connections, where a non-secret session ID is trusted without re-validating authentication tokens. As a result, newly created session IDs can be logged, leading to potential privilege escalation and extensive code execution across the infrastructure. Security measures are necessary to mitigate risks associated with session hijacking.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).
.