CVE-2026-81658 PUBLISHED

Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup

Assigner: redhat
Reserved: 27.08.2026 Published: 27.08.2026 Updated: 27.08.2026

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS Score: 6.5

Product Status

Vendor Red Hat
Product Red Hat Satellite 6
Versions Default: affected

Workarounds

Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.

Credits

  • Red Hat would like to thank Arpit Jain, Independent Security Researcher (Github: arpitjain099) for reporting this issue.

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE