---
id: CVE-2026-79654
title: >-
  A flaw was found in Katello where the Content View History API does not
  properly enforce authorization when accessing a Content View specified by the
  user
summary: >-
  A flaw was found in Katello where the Content View History API does not
  properly enforce authorization when accessing a Content View specified by the
  user. An authenticated user with permission to view Content Views in one
  organization m…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-639
vendor: Red Hat
product: rubygem-katello
affected:
  - rubygem-katello (all versions)
  - 'satellite:el8/rubygem-katello (all versions)'
  - tfm-rubygem-katello
published: '2026-08-26'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T12:17:07.460'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79654'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-79654'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2523348'
    label: secalert@redhat.com
  - url: 'https://github.com/Katello/katello/pull/11847'
    label: secalert@redhat.com
  - url: 'https://projects.theforeman.org/issues/39701'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79654.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-79654'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79654'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-28T22:44:51.099934Z'
epss: 0.00328
epssPercentile: 0.26113
ingestedAt: '2026-08-29T21:42:34.440Z'
---

## Overview

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Satellite 6 · no fix planned: Red Hat Satellite 6 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-79654.json)
