Authorization Bypass Vulnerability in Katello by Red Hat
CVE-2026-56098

4.3MEDIUM

What is CVE-2026-56098?

An authorization bypass vulnerability exists in the RegistryProxiesController of Katello, attributed to a flawed execution flow in the registry_authorize filter. This flaw allows unauthorized requests to pass through without proper termination, which leads to the execution of subsequent logic and potential exposure of sensitive database information. An unprivileged attacker can exploit this flaw to enumerate valid Users, Organizations, and Products, thereby revealing critical internal state information through inconsistent response outputs.

Affected Version(s)

Red Hat Satellite 6.19 for RHEL 9 0:4.20.0.11-1.el9sat

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).
.