Command Injection Vulnerability in Foreman by Red Hat
CVE-2026-12540

8.2HIGH

What is CVE-2026-12540?

A command injection vulnerability has been identified in Foreman, specifically within the foreman-rake errors:fetch_log task. This vulnerability allows an attacker with sudo permissions to exploit the request_id parameter, which is improperly handled when passed to system commands such as grep. By injecting shell metacharacters, an attacker can manipulate the command execution process, leading to the possibility of executing arbitrary code. This flaw emphasizes the need for stringent input validation and proper handling of command parameters to prevent unauthorized command executions.

Affected Version(s)

Red Hat Satellite 6.19 for RHEL 9 0:3.18.0.14-1.el9sat

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).
.