๐Ÿ” CVE Alert

CVE-2026-12405

HIGH 8.8

Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user.

CWE CWE-78
Vendor red hat
Product red hat satellite 6.19 for rhel 9
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat satellite 6.19 for rhel 9

Be the first to know when new high vulnerabilities affecting red hat red hat satellite 6.19 for rhel 9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Red Hat / Red Hat Satellite 6.19 for RHEL 9
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:74503 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-12405 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2488952

Credits

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).