---
id: CVE-2026-92894
title: A flaw was found in the foreman_ansible plugin's Ansible override values API
summary: >-
  A flaw was found in the foreman_ansible plugin's Ansible override values API.
  The destroy action resolves the target LookupValue record by ID without
  verifying it belongs to an AnsibleVariable the caller is authorized to edit.
  An authent…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-863
vendor: Red Hat
product: rubygem-foreman_ansible
affected:
  - rubygem-foreman_ansible (all versions)
published: '2026-09-17'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:06:08.407'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92894'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2026-92894'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2535902'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92894.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-92894'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92894'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00264
epssPercentile: 0.16269
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-17T14:31:59.210371Z'
ingestedAt: '2026-09-17T10:15:37.164Z'
---

## Overview

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user with the edit_ansible_variables permission can delete any LookupValue by ID, including override values for Ansible variables outside their permission filter scope and override values belonging to Puppet smart class parameters.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Satellite 6 · no fix planned: Red Hat Satellite 6 · updated 2026-09-17 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-92894.json)
