PT-2026-94205 · Foreman · Foreman Ansible Plugin

·

CVE-2026-92894

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions foreman ansible plugin (affected versions not specified)
Description A flaw exists in the Ansible override values API of the foreman ansible plugin. The destroy action resolves the target LookupValue record by ID but fails to verify if the record belongs to an AnsibleVariable that the caller is authorized to edit. Consequently, an authenticated user possessing the edit ansible variables permission can delete any LookupValue by ID. This includes override values for Ansible variables outside their permission filter scope and override values associated with Puppet smart class parameters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92894

Affected Products

Foreman Ansible Plugin