Command Injection Vulnerability in Hammer CLI and Railties by Red Hat
CVE-2026-12545
6.7MEDIUM
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-12545?
A command injection vulnerability was identified in Hammer CLI and the Railties component of Ruby on Rails distributed with Satellite. This flaw arises from the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. The exploitation of this vulnerability occurs when an attacker is able to pass a malformed string to the system() method, which results in invoking a system shell that unwittingly interprets shell metacharacters. If exploited, this vulnerability could lead to undesired execution of commands within the system, enhancing the risk of a security breach.
Affected Version(s)
Red Hat Satellite 6.19 for RHEL 9 0:3.18.0-2.el9sat
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).