CVE-2026-96659
Received Received - Intake

Information Disclosure and RCE in Foreman via Template Preview

Vulnerability report for CVE-2026-96659, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: redhat-SADP

Description

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
foreman foreman *
red_hat foreman *
red_hat satellite 6.19.5

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-267 A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-96659 is a flaw in Foreman, a lifecycle management tool. It allows an authenticated user with Viewer permissions to access sensitive data like host root passwords by exploiting template preview endpoints. If Safemode protections are disabled, the flaw may also permit executing arbitrary commands as the Foreman system account.

Detection Guidance

Check Foreman logs for unauthorized access to template preview endpoints like POST /template/preview. Monitor for unusual requests from users with Viewer permissions. Inspect system logs for commands executed by the Foreman system account.

Impact Analysis

This vulnerability can lead to unauthorized disclosure of sensitive information such as host root passwords. It may also allow attackers to execute arbitrary commands on the system as the Foreman account, potentially causing further compromise of the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data such as host root passwords, which may violate compliance requirements under GDPR (for personal data protection) and HIPAA (for protected health information). Unauthorized disclosure or execution of arbitrary commands could result in data breaches, triggering legal and regulatory penalties.

Mitigation Strategies

Restrict Viewer role permissions to prevent access to sensitive endpoints. Enable Safemode protections if disabled. Apply Foreman updates or patches as soon as available. Review and audit user permissions regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96659. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart