CVE-2026-96658
Received Received - Intake

Remote Code Execution in Foreman via Templating Engine Bypass

Vulnerability report for CVE-2026-96658, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
redhat foreman *
red_hat foreman *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a safemode bypass flaw in Foreman, a component of Red Hat Satellite. An authenticated attacker with low-level permissions can achieve remote code execution by exploiting improper handling of delegated methods in the templating engine. They append unauthorized functions to the allowed execution list, enabling arbitrary command execution on the hosting server.

Detection Guidance

Detecting this vulnerability requires checking Foreman versions and reviewing templating engine logs for suspicious activity. Use commands like 'rpm -q foreman' to verify installed versions and inspect Safemode bypass attempts in template rendering logs. Security scanners compatible with Red Hat's backporting practices can also help identify affected systems.

Impact Analysis

An attacker with minimal read permissions could execute arbitrary code on the Satellite server, potentially leading to full system compromise. This includes unauthorized data access, modification, or deletion, and could disrupt services. The high CVSS score (9.9) indicates severe impact on confidentiality, integrity, and availability.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating compliance requirements under GDPR (data protection) and HIPAA (health information). Organizations using Foreman may face legal penalties, reputational damage, and loss of certification if exploited.

Mitigation Strategies

Immediately upgrade Foreman to the latest patched version. If upgrading is not possible, apply mitigations provided by Red Hat or consult a Technical Account Manager. Restrict user permissions to the minimum required and monitor for unauthorized template execution attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96658. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart