CVE-2026-12112 PUBLISHED

Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse

Assigner: redhat
Reserved: 12.06.2026 Published: 23.06.2026 Updated: 24.06.2026

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor Red Hat
Product Red Hat Satellite 6.19
Versions Default: affected
  • unaffected from 1782228692 to * (excl.)

Workarounds

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Credits

  • This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).

References

Problem Types

  • Improper Authentication CWE