Authentication Bypass Vulnerability in Red Hat Satellite
CVE-2026-12423
7.5HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-12423?
An authentication bypass vulnerability exists in the Red Hat Satellite's /unattended/provision API endpoint due to a flaw in the host_verifier.rb logic. This issue allows unauthorized access to the kickstart template, as the system mistakenly validates a provisioning token's database presence instead of verifying the token included in the HTTP request. Consequently, even without a token, an attacker can exploit an active provisioning session that contains a valid token in the database, thus bypassing authentication checks.
Affected Version(s)
Red Hat Satellite 6.19 for RHEL 9 0:3.18.0.14-1.el9sat
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).