Vendor
high
advisory
Command Injection in Red Hat Satellite (CVE-2026-12405)
2 rules 3 TTPs 1 CVEA command injection vulnerability in the rubygem-foreman_remote_execution component allows authenticated attackers to execute arbitrary shell commands via the Satellite API.
Satellite +1
vulnerability
command-injection
server-side
web-application-vulnerability
authentication-bypass
cve-2026-12423
2r
3t
1c
critical
advisory
Remote Code Execution in Foreman via Safemode Sandbox Bypass
4 TTPs 4 CVEsAn authenticated, low-privileged attacker can achieve remote code execution in Foreman by bypassing the templating engine's safemode sandbox to invoke unauthorized functions.
Foreman
rce
vulnerability
webserver
information-disclosure
command-injection
4t
4c
updated