{"id":"CVE-2026-1961","title":"A flaw was found in Foreman","summary":"A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resou…","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-78","CWE-78"],"published":"2026-03-26","updated":"2026-06-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-1961","references":[{"url":"https://access.redhat.com/errata/RHSA-2026:5968","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:5970","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2026:5971","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2026-1961","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2437036","label":"secalert@redhat.com"},{"url":"http://www.openwall.com/lists/oss-security/2026/03/27/3","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2026:5968","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:5970","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/errata/RHSA-2026:5971","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-1961","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2437036","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-1961.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"}],"tags":["nvd","exploit-available"],"epss":0.01408,"epssPercentile":0.7145,"ingestedAt":"2026-07-01T03:50:34.542Z","exploits":{"github":1,"githubRepos":["https://github.com/kalnux/CVE-2026-1961-foreman-poc"],"checkedAt":"2026-09-23T07:13:52.954Z"},"exploitAvailable":true,"slug":"CVE-2026-1961","body":"## Overview\n\nA flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":44,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[{"seq":207747,"id":"CVE-2026-1961","ts":1789836173233,"field":"exploit_available","old":"false","new":"true"}]}