OS Command Injection Vulnerability in Foreman by Red Hat
CVE-2026-12542
5.3MEDIUM
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-12542?
A vulnerability in the Foreman utility allows an attacker to exploit the foreman-tail script through OS command injection. The flaw arises from the unsafe use of the eval command, where unsanitized user inputs are directly executed. By leveraging shell metacharacters, a local attacker can execute arbitrary system commands, posing a significant threat to system security. This issue emphasizes the necessity for input validation and proper containment in command execution functions.
Affected Version(s)
Red Hat Satellite 6.19 for RHEL 9 0:3.18.0.14-1.el9sat
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).