{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/foreman/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:red_hat:satellite:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-12405"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Satellite","Foreman"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","server-side","web-application-vulnerability","authentication-bypass","cve-2026-12423"],"_cs_type":"advisory","_cs_vendors":["Red Hat","Foreman"],"content_html":"\u003cp\u003eCVE-2026-12405 is a command injection vulnerability affecting the rubygem-foreman_remote_execution component within Red Hat Satellite. The issue stems from insufficient input sanitization of the 'effective_user' parameter within the /api/v2/job_invocations endpoint. When a job template is configured with the 'effective_user' property set to 'overridable: true', an authenticated user with sufficient permissions to execute job templates can inject malicious shell commands. These commands are executed by the Satellite server during the instantiation of the job execution environment. Because the injection occurs at the API level rather than within the job template content itself, attackers can bypass intended restrictions, leading to arbitrary code execution on the infrastructure with the privileges of the defined execution user.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated user to gain arbitrary command execution on Red Hat Satellite infrastructure. This vulnerability poses a high risk to environment integrity, as it grants attackers the ability to execute commands with the privileges of the targeted execution user, potentially leading to privilege escalation, lateral movement, or full compromise of the Satellite server and managed infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview all Job Templates in Red Hat Satellite and identify templates where the 'effective_user' property is set to 'overridable: true'.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls for users with permissions to execute job templates to limit the exposure to this API endpoint.\u003c/li\u003e\n\u003cli\u003eApply patches provided by Red Hat as soon as they become available to address the underlying sanitization flaw in rubygem-foreman_remote_execution.\u003c/li\u003e\n\u003cli\u003eAudit logs for anomalous POST requests to the /api/v2/job_invocations endpoint, specifically monitoring the 'effective_user' field for shell metacharacters or unexpected input patterns.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T18:13:20Z","date_published":"2026-10-01T18:13:10Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-12405/","summary":"A command injection vulnerability in the rubygem-foreman_remote_execution component allows authenticated attackers to execute arbitrary shell commands via the Satellite API.","title":"Command Injection in Red Hat Satellite (CVE-2026-12405)","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-12405/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:foreman:foreman:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2026-96658"},{"cvss":9.1,"id":"CVE-2026-96659"},{"cvss":8.2,"id":"CVE-2026-12540"},{"cvss":7.7,"id":"CVE-2026-12544"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Foreman"],"_cs_severities":["critical"],"_cs_tags":["rce","vulnerability","webserver","information-disclosure","command-injection","foreman"],"_cs_type":"advisory","_cs_vendors":["Foreman"],"content_html":"\u003cp\u003eCVE-2026-96658 is a critical security vulnerability impacting Foreman, a lifecycle management tool for physical and virtual servers. The flaw exists within the application's templating engine, specifically regarding the implementation of the safemode sandbox designed to restrict untrusted code execution.\u003c/p\u003e\n\u003cp\u003eThe vulnerability allows an authenticated attacker with low-level permissions to manipulate the templating engine by abusing the handling of delegated methods. By appending unauthorized functions to the application's allowed execution list, the attacker can break out of the sandbox environment. This results in the ability to execute arbitrary commands with the privileges of the underlying web server process. Given the core management capabilities of Foreman, successful exploitation provides a significant vector for full infrastructure compromise. Defenders should prioritize updating Foreman instances to the latest patched version once available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows authenticated attackers to move from low-level access to full remote code execution on the hosting server. This capability enables complete control over the Foreman instance, potential lateral movement into managed compute nodes, and access to stored credentials or system configuration data.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching Foreman as soon as the vendor releases the security update addressing CVE-2026-96658. Until a patch is available, audit user access levels and restrict template management permissions to trusted administrative roles to minimize the pool of potential attackers.\u003c/p\u003e\n","date_modified":"2026-10-02T14:20:35Z","date_published":"2026-10-01T18:12:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-foreman-rce/","summary":"An authenticated, low-privileged attacker can achieve remote code execution in Foreman by bypassing the templating engine's safemode sandbox to invoke unauthorized functions.","title":"Remote Code Execution in Foreman via Safemode Sandbox Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-foreman-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Foreman","version":"https://jsonfeed.org/version/1.1"}