PT-2026-103918 · Red Hat · Red Hat Satellite 6+1

·

CVE-2026-12541

·

Publicado

2026-10-01

·

Atualizado

2026-10-01

CVSS v3.1

8.2

Alta

VetorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-12541

Produtos afetados

Red Hat Satellite 6
Red Hat Satellite 6.19 For Rhel 9