{"api_version":"1","generated_at":"2026-10-01T21:51:29+00:00","cve":"CVE-2026-96659","urls":{"html":"https://cve.report/CVE-2026-96659","api":"https://cve.report/api/cve/CVE-2026-96659.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-96659","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-96659"},"summary":{"title":"Foreman: excessive permissions for viewer role on preview","description":"A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.","state":"PUBLISHED","assigner":"redhat","published_at":"2026-10-01 17:17:35","updated_at":"2026-10-01 20:36:15"},"problem_types":["CWE-267","CWE-267 Privilege Defined With Unsafe Actions"],"metrics":[{"version":"3.1","source":"secalert@redhat.com","type":"Primary","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"9.1","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","version":"3.1"}}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2026:74503","name":"https://access.redhat.com/errata/RHSA-2026:74503","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536844","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2536844","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2026-96659","name":"https://access.redhat.com/security/cve/CVE-2026-96659","refsource":"secalert@redhat.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-96659","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96659","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Red Hat","product":"Red Hat Satellite 6.19 for RHEL 9","version":"unaffected 0:3.18.0.14-1.el9sat * rpm","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-09-17T20:53:34.569Z","lang":"en","value":"Reported to Red Hat."},{"source":"CNA","time":"2026-10-01T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:satellite:6.19::el9","cpe:/a:redhat:satellite_capsule:6.19::el9","cpe:/a:redhat:satellite_utils:6.19::el9"],"defaultStatus":"affected","packageName":"foreman","product":"Red Hat Satellite 6.19 for RHEL 9","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"0:3.18.0.14-1.el9sat","versionType":"rpm"}]}],"datePublic":"2026-10-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-267","description":"Privilege Defined With Unsafe Actions","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-01T16:23:23.666Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2026:74503","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:74503"},{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2026-96659"},{"name":"RHBZ#2536844","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2536844"}],"timeline":[{"lang":"en","time":"2026-09-17T20:53:34.569Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-10-01T00:00:00.000Z","value":"Made public."}],"title":"Foreman: excessive permissions for viewer role on preview","x_generator":{"engine":"cvelib 1.8.0"},"x_redhatCweChain":"CWE-267: Privilege Defined With Unsafe Actions"}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2026-96659","datePublished":"2026-10-01T16:23:23.666Z","dateReserved":"2026-09-23T14:46:49.272Z","dateUpdated":"2026-10-01T16:23:23.666Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-01 17:17:35","lastModifiedDate":"2026-10-01 20:36:15","problem_types":["CWE-267","CWE-267 Privilege Defined With Unsafe Actions"],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L","baseScore":9.1,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":3.1,"impactScore":5.3}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"96659","Ordinal":"1","Title":"Foreman: excessive permissions for viewer role on preview","CVE":"CVE-2026-96659","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"96659","Ordinal":"1","NoteData":"A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.","Type":"Description","Title":"Foreman: excessive permissions for viewer role on preview"}]}}}