CVE-2026-12541
Received Received - Intake

Command Injection in Foreman Rake Tasks

Vulnerability report for CVE-2026-12541, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
foreman foreman *
red_hat foreman From 6.19.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12541 is a command injection flaw in Foreman (Red Hat Satellite) affecting the foreman-rake db:dump and db:import_dump tasks. The vulnerability occurs because user input in the destination and file parameters is not properly sanitized before being passed to a Ruby system() call. Attackers with foreman-rake permissions can inject malicious shell commands by appending them to file paths, leading to privilege escalation and arbitrary command execution.

Detection Guidance

Check for suspicious foreman-rake db:dump or db:import_dump commands in system logs. Look for unusual file paths or appended shell commands in parameters like destination or file. Review sudoers configuration for foreman-rake permissions.

Impact Analysis

Exploitation allows attackers to escalate privileges to the foreman account, gain control over the Satellite database and configurations, move laterally within the network, and execute commands with full root privileges on all managed hosts. This could lead to complete system compromise, data theft, or disruption of services.

Compliance Impact

This vulnerability could lead to unauthorized access, data breaches, or loss of sensitive information, violating compliance requirements such as GDPR (data protection) and HIPAA (healthcare data privacy). Organizations may face legal penalties, reputational damage, and loss of trust due to non-compliance resulting from exploitation of this flaw.

Mitigation Strategies

Apply the latest patches from Red Hat immediately. Restrict sudo permissions for foreman-rake to only necessary users. Implement strict input validation for filesystem paths in database tasks. Avoid using shell-based execution methods in Ruby scripts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12541. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart