Authorization Flaw in Katello Affects Lifecycle Information Access
CVE-2026-79654
4.3MEDIUM
What is CVE-2026-79654?
A security flaw has been identified in Katello affecting the Content View History API, where authorization checks are insufficient. Authenticated users permitted to access Content Views within their organization may exploit this vulnerability to gain unauthorized access to the lifecycle history of Content Views from other organizations. By manipulating the API endpoint with a specific Content View identifier, sensitive lifecycle information—including publication and promotion events, associated user data, and relevant timestamps—may be disclosed improperly. This highlights a significant risk to data confidentiality across organizational boundaries.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Arpit Jain, Independent Researcher (Github: arpitjain099) for reporting this issue.