CVE-2026-107445
Received Received - Intake

Authorization Bypass in Katello Flatpak Remote Repositories

Vulnerability report for CVE-2026-107445, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: redhat-SADP

Description

A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat katello *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107445 is a flaw in Katello's Flatpak Remote Repositories API where authorization is not properly enforced. An authenticated user with view permissions in one organization can access another organization's Flatpak remote repository data due to an unscoped lookup. This also allows creating repositories using another organization's remote URL and credentials.

Detection Guidance

Check Katello logs for unauthorized access attempts to Flatpak remote repositories across organizations. Look for API calls using FlatpakRemoteRepository.find without proper scoping. Review user permissions for view_flatpak_remotes and ensure they are restricted to their own organization.

Impact Analysis

This vulnerability allows unauthorized access to sensitive repository data across organizations. Attackers could view or manipulate repositories they shouldn't have access to, potentially leading to data leaks or unauthorized modifications. The mirror action could enable repository creation using stolen credentials.

Compliance Impact

This vulnerability could lead to unauthorized data access across organizations, violating data segregation requirements in GDPR and HIPAA. It may result in non-compliance due to potential exposure of sensitive information to unauthorized users.

Mitigation Strategies

Upgrade the rubygem-katello package to a fixed version. Temporarily restrict view_flatpak_remotes permissions to prevent unauthorized access. Monitor API calls to Flatpak remote repositories for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107445. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart