CVE-2026-5142
Analyzed
Analyzed - Analysis Complete
Authenticated users can bypass taxonomy scoping to download private SSH keys in Foreman
Vulnerability report for CVE-2026-5142, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-01
Last updated on: 2026-07-09
Assigner: Red Hat, Inc.
Description
Description
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| redhat | satellite | From 6.18 (inc) to 6.18.7 (exc) |
| redhat | satellite | From 6.16 (inc) to 6.16.10 (exc) |
| redhat | satellite | From 6.17 (inc) to 6.17.9 (exc) |
| redhat | satellite | From 6.19 (inc) to 6.19.2 (exc) |
| theforeman | foreman | to 3.18.2 (exc) |
| theforeman | foreman | From 3.19.0 (inc) to 3.19.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |