Authorization Flaw in Foreman's Template Revision Endpoint
CVE-2026-81658

6.5MEDIUM

Key Information:

Vendor

Red Hat

Vendor
CVE Published:
27 August 2026

What is CVE-2026-81658?

A vulnerability exists in Foreman's template revision endpoint that allows an authenticated user with limited permissions to access sensitive, historical template contents from other organizations or locations. By exploiting this flaw, the user can retrieve information tied to a specific audit ID, leading to potential exposure of configuration data, secrets, or credentials that should remain confidential. Notably, while the REST API revision endpoints are restrictive, this particular endpoint fails to enforce object-level authorization, creating unnecessary risks for organizations relying on Foreman for template management.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Arpit Jain, Independent Security Researcher (Github: arpitjain099) for reporting this issue.
.