Foreman · Foreman · CVE-2026-5138
**Name of the Vulnerable Software and Affected Versions**
Foreman (affected versions not specified)
**Description**
An authenticated user with host-edit permissions can exploit a cross-tenant information disclosure flaw. The issue exists because the `taxonomy scope` controller method fails to properly validate organization and location IDs within nested request parameters, which bypasses authorization checks. This allows an attacker to leak sensitive infrastructure metadata from unauthorized organizations and locations, including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.