Skip to content
Threat Feed
high advisory

Authorization Bypass Vulnerability in Candlepin

A flaw in the Candlepin authorization filter allows low-privileged authenticated users to bypass security checks and access unauthorized resources by exploiting flawed parameter verification.

CVE search metadata

CVE search record: CVE-2026-106471. Severity: high. CVSS: 8.1. KEV: no. Product: Candlepin. Brief: Authorization Bypass Vulnerability in Candlepin. Brief link: https://feed.craftedsignal.io/briefs/2026-10-07-candlepin-auth-bypass/

A vulnerability identified as CVE-2026-106471 exists within the Candlepin authorization framework. The issue stems from the central authorization filter failing to correctly implement logic for '@Verify-annotated' parameters. Instead of enforcing that all required entities associated with a request are verified, the filter grants access if at least one parameter is accessible. This allows a low-privilege authenticated attacker to bypass authorization checks on subsequent objects. By identifying target resource identifiers, an attacker can access sensitive consumer information and potentially modify entitlements and subscription resources across different organizational boundaries. This vulnerability poses a significant risk to the integrity and confidentiality of subscription management data.

Impact

The vulnerability enables unauthorized information disclosure and unauthorized modification of subscription resources. Successful exploitation allows low-privileged users to perform actions outside their permitted scope, potentially affecting resources across organizations, which could lead to significant data breaches and administrative misconfiguration of subscription environments.

Recommendation

Prioritize applying the vendor-supplied security patches for Candlepin to resolve the flawed authorization filter logic. Monitor system access logs for anomalous, high-frequency requests targeting sensitive resource identifiers that typically require elevated privileges.


Immediate actions

Patch all instances of Candlepin with the version provided by Red Hat.

IT Operations 48h

Threat Hunt

Identify multiple 403 Forbidden errors followed by successful requests to sensitive subscription resource endpoints from low-privilege accounts.

T1068 medium medium confidence hunt now

Data: Web server access logs