PT-2026-103944 · Red Hat · Red Hat Satellite 6.19 For Rhel 9

CVE-2026-96658

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling them to run arbitrary commands on the hosting server.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-96658

Affected Products

Red Hat Satellite 6.19 For Rhel 9