PT-2026-103959 · Red Hat · Red Hat Satellite 6+1

·

CVE-2026-56097

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check blob push org label and get matching products from org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create personal access tokens permission, even if the user access is restricted, with no Organization or Location assigned.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56097

Affected Products

Red Hat Satellite 6
Red Hat Satellite 6.19 For Rhel 9