PT-2026-82490 · Foreman · Foreman

·

CVE-2026-81658

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Foreman (affected versions not specified)
Description An issue exists where the template revision endpoint fails to enforce object-level authorization when retrieving an audited template revision. An authenticated user with low privileges and template-related permissions, such as view ptables, can access historical template contents from other organizations or locations by providing the relevant audit ID. This may lead to the unauthorized disclosure of sensitive data, including configuration details, credentials, or secrets. The REST API revision endpoints are not affected by this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81658

Affected Products

Foreman