OS Command Injection Vulnerability in Foreman by Red Hat
CVE-2026-12542

5.3MEDIUM

What is CVE-2026-12542?

A vulnerability in the Foreman utility allows an attacker to exploit the foreman-tail script through OS command injection. The flaw arises from the unsafe use of the eval command, where unsanitized user inputs are directly executed. By leveraging shell metacharacters, a local attacker can execute arbitrary system commands, posing a significant threat to system security. This issue emphasizes the necessity for input validation and proper containment in command execution functions.

Affected Version(s)

Red Hat Satellite 6.19 for RHEL 9 0:3.18.0.14-1.el9sat

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).
.