HIGH 7.5 NVD
CVE-2026-12423
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
References
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/security/cve/CVE-2026-12423
- https://bugzilla.redhat.com/show_bug.cgi?id=2488956
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-10-01 via NVD.
vulnfeed aggregates 9446 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.