Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
118 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.7) | 0.51% | — | Theforeman Hammer CLIAI | 1/10/2026 | 2/10/2026 | A flaw was found in rubygem-hammer_cli. A command injection vulnerability exists in Hammer CLI and the Railties (Ruby on Rails) component distributed with Satellite due to the insecure interpolation of the $EDITOR environment variable into the Ruby system() method. By passing a single interpolated string to system(),… | |
| Pendiente de análisis | Media (5.3) | 0.55% | — | Theforeman ForemanAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted,… | |
| Pendiente de análisis | Crítica (9.1) | 0.32% | — | Theforeman ForemanAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under… | |
| Pendiente de análisis | Crítica (9.9) | 0.70% | — | Theforeman ForemanAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an attacker can append unauthorized functions to the allowed execution list, enabling… | |
| Pendiente de análisis | Alta (7.7) | 0.22% | — | Theforeman ForemanAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection… | |
| Pendiente de análisis | Alta (8.2) | 1.3% | — | Theforeman ForemanAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call… | |
| Pendiente de análisis | Alta (8.2) | 1.3% | — | Theforeman ForemanAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo… | |
| Pendiente de análisis | Alta (7.5) | 0.38% | — | Redhat ForemanAIRedhat SatelliteAI | 1/10/2026 | 2/10/2026 | A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a… | |
| Pendiente de análisis | Alta (8.8) | 1.5% | — | Foreman Remote ExecutionAI | 1/10/2026 | 2/10/2026 | A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the… | |
| Pendiente de análisis | Media (4.3) | 0.34% | — | Theforeman Foreman Remote ExecutionAI | 17/9/2026 | 18/9/2026 | A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is… | |
| Pendiente de análisis | Media (4.3) | 0.28% | — | Theforeman Foreman AnsibleAI | 17/9/2026 | 18/9/2026 | A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticated user whose host visibility is restricted by a permission filter can… | |
| Pendiente de análisis | Media (4.3) | 0.26% | — | Theforeman Foreman AnsibleAI | 17/9/2026 | 18/9/2026 | A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user with the edit_ansible_variables permission can delete any LookupValue… | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Theforeman ForemanAI | 27/8/2026 | 28/8/2026 | A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization… | |
| Analizada | Media (6.5) | 0.45% | — | Redhat SatelliteTheforeman Foreman | 1/7/2026 | 9/7/2026 | A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments,… | |
| Analizada | Media (4.3) | 0.38% | — | Redhat SatelliteTheforeman Foreman | 1/7/2026 | 9/7/2026 | A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxonomy_scope controller method does not properly validate organization and location IDs from nested request parameters, bypassing existing… | |
| Analizada | Media (6.5) | 0.43% | — | Redhat SatelliteTheforeman Foreman | 1/7/2026 | 9/7/2026 | A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The… | |
| Analizada | Alta (8.8) | 0.56% | — | Redhat SatelliteTheforeman Foreman | 1/7/2026 | 9/7/2026 | A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a… | |
| Analizada | Media (4.4) | 0.15% | — | Redhat SatelliteTheforeman Foreman | 30/6/2026 | 6/7/2026 | A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component. | |
| Modificada | Media (6.2) | 0.21% | — | Redhat SatelliteTheforeman Foreman | 23/6/2026 | 15/7/2026 | A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The other, when debug logging is enabled,… | |
| Modificada | Alta (7.8) | 0.22% | — | Redhat SatelliteTheforeman Foreman | 23/6/2026 | 16/7/2026 | A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by… | |
| Pendiente de análisis | Alta (8) | 1.4% | — | Theforeman ForemanAI | 26/3/2026 | 15/7/2026 | A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute… | |
| Modificada | Media (6.5) | 0.35% | — | Theforeman ForemanRedhat SatelliteRedhat Satellite CapsuleRedhat Enterprise Linux | 27/2/2026 | 17/6/2026 | n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass. | |
| Aplazada | Alta (8.1) | 0.30% | — | Foreman KubevirtAI | 2/2/2026 | 15/7/2026 | A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform… | |
| Aplazada | Alta (8) | 0.58% | — | Redhat SatelliteAITheforeman ForemanAI | 5/11/2025 | 17/6/2026 | A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_settings permissions to achieve arbitrary command execution on the underlying operating system via insufficient server-side validation of command whitelisting. | |
| Aplazada | Baja (3.3) | 0.15% | — | Redhat SatelliteAITheforeman ForemanAI | 15/3/2025 | 17/6/2026 | A flaw was found in Foreman/Red Hat Satellite. Improper file permissions allow low-privileged OS users to monitor and access temporary files under /var/tmp, exposing sensitive command outputs, such as /etc/shadow. This issue can lead to information disclosure and privilege escalation if exploited effectively. |