CVE-2026-12405
Received Received - Intake

Remote Code Execution in Foreman Remote Execution

Vulnerability report for CVE-2026-12405, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
red_hat foreman_remote_execution *
red_hat rubygem-foreman_remote_execution *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a command injection vulnerability in Red Hat Satellite's API endpoint /api/v2/job_invocations within the rubygem-foreman_remote_execution component. When a job template's effective_user property is set as overridable, the application fails to sanitize user input for this parameter. Attackers with job execution permissions can inject arbitrary shell commands into the effective_user field, which are then executed on managed hosts with the execution user's privileges.

The vulnerability occurs during job execution environment setup and does not depend on the job template's content or logic. It allows attackers to bypass playbook restrictions, escalate privileges, and gain full administrative control over managed infrastructure.

Detection Guidance

To detect this vulnerability, check if your Red Hat Satellite server has the rubygem-foreman_remote_execution package installed and if the API endpoint /api/v2/job_invocations is accessible. Review job templates for the effective_user property set as overridable. Monitor logs for suspicious API requests or command execution patterns.

Impact Analysis

An attacker could gain full administrative control over your managed hosts, execute arbitrary commands with elevated privileges, and compromise the confidentiality, integrity, and availability of your entire infrastructure. This could lead to data breaches, unauthorized access to sensitive systems, and disruption of critical services.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for GDPR (data protection), HIPAA (health information), and other regulations. A successful exploit may result in data breaches, unauthorized disclosures, and failure to maintain data integrity and confidentiality, potentially leading to legal penalties and reputational damage.

Mitigation Strategies

Immediately update the rubygem-foreman_remote_execution package to the latest version. Disable the overridable effective_user property in job templates. Implement strict input validation for the effective_user parameter. Ensure the execution engine uses safe API calls without shell evaluation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12405. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart