SQL Injection Vulnerability in Red Hat Satellite Katello Registry Proxy
CVE-2026-56097
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-56097?
An SQL injection gap has been identified in the Red Hat Satellite Katello Registry Proxy, specifically related to the rubygem-katello component. The flaw arises from improper sanitization of input parameters used in database queries within the RegistryProxiesController. This vulnerability allows an attacker to incorporate user-supplied labels directly into SQL fragments via methods like check_blob_push_org_label and get_matching_products_from_org. Alarmingly, it can be exploited by a user possessing only the create_personal_access_tokens permission, even when their access is limited, without any assigned Organization or Location, potentially leading to unauthorized access to sensitive data.
Affected Version(s)
Red Hat Satellite 6.19 for RHEL 9 0:4.20.0.11-1.el9sat
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved