Command Injection Vulnerability in Foreman by Red Hat
CVE-2026-12540
8.2HIGH
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-12540?
A command injection vulnerability has been identified in Foreman, specifically within the foreman-rake errors:fetch_log task. This vulnerability allows an attacker with sudo permissions to exploit the request_id parameter, which is improperly handled when passed to system commands such as grep. By injecting shell metacharacters, an attacker can manipulate the command execution process, leading to the possibility of executing arbitrary code. This flaw emphasizes the need for stringent input validation and proper handling of command parameters to prevent unauthorized command executions.
Affected Version(s)
Red Hat Satellite 6.19 for RHEL 9 0:3.18.0.14-1.el9sat
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).