PT-2026-103917 · Red Hat · Red Hat Satellite 6+1

·

CVE-2026-12540

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch log task. The request id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12540

Affected Products

Red Hat Satellite 6
Red Hat Satellite 6.19 For Rhel 9