PT-2026-103916 · Red Hat · Red Hat Satellite 6+1

·

CVE-2026-12423

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid host token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12423

Affected Products

Red Hat Satellite 6
Red Hat Satellite 6.19 For Rhel 9