CVE-2026-5142
EUVD-2026-4100201.07.2026, 15:17
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | satellite | 6.18 ≤ 𝑥 < 6.18.7 |
| redhat | satellite | 6.16 ≤ 𝑥 < 6.16.10 |
| redhat | satellite | 6.17 ≤ 𝑥 < 6.17.9 |
| redhat | satellite | 6.19 ≤ 𝑥 < 6.19.2 |
| theforeman | foreman | 𝑥 < 3.18.2 |
| theforeman | foreman | 3.19.0 ≤ 𝑥 < 3.19.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
Vulnerability Media Exposure
References