CVE-2026-56098Medium· 4.3▾ SunlitA flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-56097Medium· 6.5A flaw was found in rubygem-katello
CVE-2026-79654Medium· 4.3A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user
CVE-2026-12545Medium· 6.7A flaw was found in rubygem-hammer_cli
CVE-2026-12542Medium· 5.3A flaw was found in Foreman
CVE-2026-96659Critical· 9.1A flaw was found in Foreman
CVE-2026-96658Critical· 9.9A flaw was found in Foreman