---
id: CVE-2026-12515
title: >-
  katello: missing repository authorization in content_uploads exposes
  cross-product content existence
summary: >-
  katello: missing repository authorization in content_uploads exposes
  cross-product content existence
severity: medium
cvss: 4.3
cwe:
  - CWE-862
vendor: katello
product: katello
ecosystem: rubygems
affected:
  - katello < 4.21.0.rc1
patched:
  - katello 4.21.0.rc1
published: '2026-06-17'
updated: '2026-06-18'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-c43c-rf7g-5xpg'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12515'
  - url: 'https://github.com/Katello/katello/pull/11712'
  - url: 'https://access.redhat.com/security/cve/CVE-2026-12515'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2489812'
  - url: 'https://github.com/advisories/GHSA-c43c-rf7g-5xpg'
tags:
  - ghsa
  - rubygems
epss: 0.00223
epssPercentile: 0.11595
ingestedAt: '2026-06-29T14:31:47.197Z'
---

## Overview

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.

## Affected packages

- `katello < 4.21.0.rc1`

## Remediation

Upgrade to a patched release:

- `katello 4.21.0.rc1`
