CVE-2026-12545
Received Received - Intake

Command Injection in Hammer CLI for Red Hat Satellite

Vulnerability report for CVE-2026-12545, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(), the application invokes a system shell (/bin/sh) that interprets shell metacharacters (e.g., ;, |, &).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
redhat rubygem-hammer_cli *
redhat railties 7.0.10
redhat satellite *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-12545 is a command injection vulnerability in rubygem-hammer_cli and Ruby on Rails' Railties component affecting Satellite. It occurs when the $EDITOR environment variable is insecurely interpolated into Ruby system() calls without sanitization. This allows shell metacharacters like ;, |, or & to be interpreted, enabling arbitrary command execution within the tool's security context.

Detection Guidance

To detect this vulnerability, check if rubygem-hammer_cli or Satellite with Railties 7.0.10 is installed. Inspect system() calls in lib/hammer_cli/utils.rb and Railties files for $EDITOR interpolation. Look for suspicious command execution patterns involving shell metacharacters.

  • Check installed versions: rpm -qa | grep hammer_cli or rpm -qa | grep railties
  • Search for vulnerable code patterns: grep -r 'system.*ENV\[.EDITOR.\]' /usr/share/hammer_cli/ /usr/share/railties/
Impact Analysis

If exploited, this vulnerability allows a local attacker to execute arbitrary commands within the context of the utility. If the utility runs with elevated permissions (e.g., via sudo preserving environment), the attacker could escalate privileges to root, leading to full system compromise. Exploitation could also result in unauthorized code execution, denial of service, or unauthorized data access/modification.

Compliance Impact

This vulnerability could lead to unauthorized code execution, data access, or modification if exploited, which may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data privacy). Unauthorized privilege escalation to root could result in full system compromise, further risking sensitive data handling.

Mitigation Strategies

Immediately stop using $EDITOR with hammer_cli or Satellite. Replace system() calls with array-based arguments to prevent shell interpretation. Upgrade to fixed versions if available. Avoid running hammer_cli with sudo while preserving environment variables.

  • Remove or restrict $EDITOR usage in hammer_cli configuration files
  • Apply patches from Satellite/Foreman engineering teams if provided
  • Monitor for unusual command execution patterns in system logs

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12545. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart