๐Ÿ” CVE Alert

CVE-2026-56098

MEDIUM 4.3

Rubygem-katello: improper authorization logic allows resource enumeration

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A flaw was found in rubygem-katello. The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement). This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.

CWE CWE-203
Vendor red hat
Product red hat satellite 6.19 for rhel 9
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for red hat red hat satellite 6.19 for rhel 9

Be the first to know when new medium vulnerabilities affecting red hat red hat satellite 6.19 for rhel 9 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None

Affected Versions

Red Hat / Red Hat Satellite 6.19 for RHEL 9
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected
Red Hat / Red Hat Satellite 6
All versions affected

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
access.redhat.com: https://access.redhat.com/errata/RHSA-2026:74503 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-56098 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2490542

Credits

This issue was discovered by Laura Pardo (Red Hat) and Toni Gornals (Red Hat).