<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:red_hat:satellite:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ared_hatsatellite/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 18:13:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ared_hatsatellite/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in Red Hat Satellite (CVE-2026-12405)</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-12405/</link><pubDate>Thu, 01 Oct 2026 18:13:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-12405/</guid><description>A command injection vulnerability in the rubygem-foreman_remote_execution component allows authenticated attackers to execute arbitrary shell commands via the Satellite API.</description><content:encoded><![CDATA[<p>CVE-2026-12405 is a command injection vulnerability affecting the rubygem-foreman_remote_execution component within Red Hat Satellite. The issue stems from insufficient input sanitization of the 'effective_user' parameter within the /api/v2/job_invocations endpoint. When a job template is configured with the 'effective_user' property set to 'overridable: true', an authenticated user with sufficient permissions to execute job templates can inject malicious shell commands. These commands are executed by the Satellite server during the instantiation of the job execution environment. Because the injection occurs at the API level rather than within the job template content itself, attackers can bypass intended restrictions, leading to arbitrary code execution on the infrastructure with the privileges of the defined execution user.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated user to gain arbitrary command execution on Red Hat Satellite infrastructure. This vulnerability poses a high risk to environment integrity, as it grants attackers the ability to execute commands with the privileges of the targeted execution user, potentially leading to privilege escalation, lateral movement, or full compromise of the Satellite server and managed infrastructure.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Review all Job Templates in Red Hat Satellite and identify templates where the 'effective_user' property is set to 'overridable: true'.</li>
<li>Implement strict access controls for users with permissions to execute job templates to limit the exposure to this API endpoint.</li>
<li>Apply patches provided by Red Hat as soon as they become available to address the underlying sanitization flaw in rubygem-foreman_remote_execution.</li>
<li>Audit logs for anomalous POST requests to the /api/v2/job_invocations endpoint, specifically monitoring the 'effective_user' field for shell metacharacters or unexpected input patterns.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>command-injection</category><category>server-side</category><category>web-application-vulnerability</category><category>authentication-bypass</category><category>cve-2026-12423</category></item></channel></rss>