CVE-2026-96658Critical· 9.9▾ MidnightA flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an a…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-12542Medium· 5.3A flaw was found in Foreman
CVE-2026-96659Critical· 9.1A flaw was found in Foreman
CVE-2026-12541High· 8.2A flaw was found in Foreman
CVE-2026-12544High· 7.7A flaw was found in Foreman
CVE-2026-12423High· 7.5A flaw was found in Foreman
CVE-2026-12540High· 8.2A flaw was found in Foreman