Remote Code Execution Vulnerability in Foreman by Red Hat
CVE-2026-96658
9.9CRITICAL
Key Information:
- Vendor
Red Hat
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-96658?
A security flaw identified in Foreman permits an authenticated attacker with minimal permissions to execute arbitrary commands on the server. This is achieved through a vulnerability in the templating engine's safemode sandbox, where improper handling of delegated methods allows the attacker to manipulate the allowed execution list. As a result, the attacker can append unauthorized functions and successfully carry out remote code execution, posing significant risks to the server's integrity.
Affected Version(s)
Red Hat Satellite 6.19 for RHEL 9 0:3.18.0.14-1.el9sat