CVE-2026-56097
Received Received - Intake

SQL Injection in Red Hat Satellite Katello Registry Proxy

Vulnerability report for CVE-2026-56097, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
red_hat rubygem_katello *
red_hat satellite *
red_hat rubygem-katello *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-56097 is an authenticated SQL injection flaw in Red Hat Satellite Katello Registry Proxy. It exists in the RegistryProxiesController where user-supplied labels from request paths are directly inserted into raw SQL queries without sanitization. The vulnerable methods are check_blob_push_org_label and get_matching_products_from_org.

Detection Guidance

To detect this SQL injection vulnerability in rubygem-katello, inspect the RegistryProxiesController in the Katello application for unsafe SQL interpolation patterns. Look for code using string interpolation like Organization.where("LOWER(label) = '#{org_label}'") or organization.products.where("LOWER(label) = '#{product_label}'"). Check logs for suspicious requests with crafted labels containing SQL fragments such as ' OR '1'='1' or UNION SELECT.

  • Review application logs for unusual database query patterns or errors related to SQL syntax.
  • Use tools like SQLMap to test for SQL injection by sending crafted payloads to endpoints handling registry proxy requests.
Impact Analysis

This vulnerability allows low-privileged users with only create_personal_access_tokens permission to bypass multi-tenancy restrictions. Attackers can exfiltrate global data by dumping the entire PostgreSQL database, including sensitive tables like users and settings. They can also perform vertical privilege escalation by extracting and cracking password hashes for admin accounts.

Compliance Impact

This SQL injection vulnerability allows low-privileged users to bypass multi-tenancy restrictions and dump the entire PostgreSQL database, including sensitive tables like users and settings. This could lead to unauthorized access to personal data, violating GDPR's data protection principles and HIPAA's safeguards for protected health information.

Mitigation Strategies

Immediately update the rubygem-katello package to the latest patched version that replaces raw SQL interpolation with parameterized queries. Ensure the fix includes changes to use ActiveRecord's safe syntax like Organization.where("LOWER(label) = ?", org_label.downcase).

  • Apply the official patch from Red Hat addressing the unsafe SQL interpolation in RegistryProxiesController methods.
  • Restrict user permissions to the minimum required, especially for create_personal_access_tokens, and enforce proper RBAC checks for Organizations and Locations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56097. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart