๐Ÿ” CVE Alert

CVE-2026-12540

HIGH 8.2

Foreman: command injection in foreman-rake errors:fetch_log via request_id parameter

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.

CWE CWE-78
Vendor red hat
Product red hat satellite 6.19 for rhel 9
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat satellite 6.19 for rhel 9

Be the first to know when new high vulnerabilities affecting red hat red hat satellite 6.19 for rhel 9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Red Hat / Red Hat Satellite 6.19 for RHEL 9
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:74503 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-12540 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2489969

Credits

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).