CVE-2026-79654
Received Received - Intake

Authorization Bypass in Katello Content View History API

Vulnerability report for CVE-2026-79654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: redhat-SADP

Description

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat katello *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Katello allows an authenticated user to access Content View lifecycle history from another organization by providing its identifier. The API fails to enforce proper authorization checks, potentially exposing sensitive information like publication events, promotion details, associated users, and timestamps.

Impact Analysis

If exploited, this flaw could allow unauthorized users to view confidential lifecycle data of Content Views belonging to other organizations. This may lead to information leaks about system configurations, user activities, or deployment timelines, potentially aiding further attacks or compliance violations.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR and HIPAA by enabling unauthorized access to sensitive lifecycle information. Such breaches may result in non-compliance penalties, reputational damage, and legal consequences due to improper handling of protected data.

Mitigation Strategies

Apply the latest Katello patches or updates to fix the authorization flaw in the Content View History API. Review API access logs for suspicious queries targeting Content View identifiers across organizations. Restrict API permissions to enforce strict role-based access control for Content View data.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79654. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart