VulnSea

satellite:el8/foreman vulnerabilities

CVEs whose affected-version data names the satellite:el8/foreman package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-12542Medium· 5.3
today

A flaw was found in Foreman

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then exe…

▾ SunlitRed Hat · foremanvia NVD
CVE-2026-12544High· 7.7
today

A flaw was found in Foreman

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a m…

▾ TwilightRed Hat · foremanvia NVD
CVE-2026-12541High· 8.2
today

A flaw was found in Foreman

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) an…

▾ TwilightRed Hat · foremanvia NVD
CVE-2026-12540High· 8.2
today

A flaw was found in Foreman

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. W…

▾ TwilightRed Hat · foremanvia NVD
CVE-2026-12423High· 7.5
today

A flaw was found in Foreman

A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioni…

▾ TwilightRed Hat · foremanvia NVD
satellite:el8/foreman vulnerabilities (CVEs) · VulnSea