CVE-2026-56098
Received Received - Intake

Authorization Bypass in Katello via RegistryProxiesController

Vulnerability report for CVE-2026-56098, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat katello *
red_hat rubygem-katello *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-203 The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authorization bypass vulnerability in rubygem-katello's RegistryProxiesController. Due to a missing return statement in the registry_authorize filter, unauthorized requests bypass access controls. Attackers can enumerate valid users, organizations, and products by observing different error responses. Invalid users trigger server crashes while valid users receive 404 errors, confirming their existence.

Detection Guidance

To detect this vulnerability, monitor HTTP responses from the RegistryProxiesController in Katello. Invalid users trigger 500 errors while valid users receive 404 errors. Use tools like curl to send test requests and observe response codes for user enumeration attempts.

Impact Analysis

An attacker could exploit this to map your system's hidden organizational structure and identify valid users, organizations, and products. This information could be used for further attacks, including data enumeration or chaining with other vulnerabilities like SQL injection. The impact is limited to information disclosure since no direct data modification or deletion occurs.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by exposing sensitive user, organization, and product data through enumeration attacks. Unauthorized access to such data may violate confidentiality requirements under these regulations.

Mitigation Strategies

Apply patches from Red Hat if available. As mitigation options are currently unavailable per Red Hat, consider temporarily disabling the RegistryProxiesController or restricting access to trusted networks until official fixes are released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-56098. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart