Privilege Escalation Vulnerability in Foreman by Red Hat
CVE-2026-5136
8.8HIGH
Key Information:
- Vendor
Red Hat
- Status
- Vendor
- CVE Published:
- 1 July 2026
What is CVE-2026-5136?
A vulnerability exists within Foreman's Usergroup model, which fails to validate role assignments based on the caller's user permissions properly. This security oversight permits an authenticated user with usergroup management rights to assign arbitrary roles, including those with administrative privileges, to any user group. By doing so, they can add themselves as a member, leading to serious security breaches that result in complete privilege escalation and unauthorized access to administrative functions.
Affected Version(s)
Red Hat Satellite 6.16 for RHEL 8 0:3.12.0.17-1.el8sat
Red Hat Satellite 6.16 for RHEL 9 0:3.12.0.17-1.el9sat
Red Hat Satellite 6.17 for RHEL 9 0:3.14.0.17-1.el9sat
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Stanislav Fot (Aisle Research) for reporting this issue.