CVE-2026-12540
Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
| CWE | CWE-78 |
| Vendor | red hat |
| Product | red hat satellite 6.19 for rhel 9 |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for red hat red hat satellite 6.19 for rhel 9
Be the first to know when new high vulnerabilities affecting red hat red hat satellite 6.19 for rhel 9 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Red Hat / Red Hat Satellite 6.19 for RHEL 9
All versions affected Red Hat / Red Hat Satellite 6
All versions affected References
Credits
This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).