Authorization Bypass Vulnerability in Candlepin
A flaw in the Candlepin authorization filter allows low-privileged authenticated users to bypass security checks and access unauthorized resources by exploiting flawed parameter verification.
CVE search metadata
CVE search record: CVE-2026-106471. Severity: high. CVSS: 8.1. KEV: no. Product: Candlepin. Brief: Authorization Bypass Vulnerability in Candlepin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-07-candlepin-auth-bypass/
A vulnerability identified as CVE-2026-106471 exists within the Candlepin authorization framework. The issue stems from the central authorization filter failing to correctly implement logic for '@Verify-annotated' parameters. Instead of enforcing that all required entities associated with a request are verified, the filter grants access if at least one parameter is accessible. This allows a low-privilege authenticated attacker to bypass authorization checks on subsequent objects. By identifying target resource identifiers, an attacker can access sensitive consumer information and potentially modify entitlements and subscription resources across different organizational boundaries. This vulnerability poses a significant risk to the integrity and confidentiality of subscription management data.
Impact
The vulnerability enables unauthorized information disclosure and unauthorized modification of subscription resources. Successful exploitation allows low-privileged users to perform actions outside their permitted scope, potentially affecting resources across organizations, which could lead to significant data breaches and administrative misconfiguration of subscription environments.
Recommendation
Prioritize applying the vendor-supplied security patches for Candlepin to resolve the flawed authorization filter logic. Monitor system access logs for anomalous, high-frequency requests targeting sensitive resource identifiers that typically require elevated privileges.
Immediate actions
Patch all instances of Candlepin with the version provided by Red Hat.
Threat Hunt
Identify multiple 403 Forbidden errors followed by successful requests to sensitive subscription resource endpoints from low-privilege accounts.
Data: Web server access logs