CVE-2026-13316
EUVD-2026-4028130.06.2026, 11:16
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | satellite | 6.0 ≤ 𝑥 ≤ 6.19 |
| theforeman | foreman | - |
𝑥
= Vulnerable software versions
Ubuntu Releases