n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
History

Fri, 27 Feb 2026 08:00:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
Title foreman: Satellite: GraphQL API permission bypass leads to information disclosure Foreman: satellite: graphql api permission bypass leads to information disclosure
First Time appeared Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
CPEs cpe:/a:redhat:satellite:6.15::el8
cpe:/a:redhat:satellite:6.16::el8
cpe:/a:redhat:satellite:6.16::el9
cpe:/a:redhat:satellite:6.17::el9
cpe:/a:redhat:satellite:6.18::el9
cpe:/a:redhat:satellite_capsule:6.15::el8
cpe:/a:redhat:satellite_capsule:6.16::el8
cpe:/a:redhat:satellite_capsule:6.16::el9
cpe:/a:redhat:satellite_capsule:6.17::el9
cpe:/a:redhat:satellite_capsule:6.18::el9
cpe:/a:redhat:satellite_utils:6.15::el8
cpe:/a:redhat:satellite_utils:6.16::el8
cpe:/a:redhat:satellite_utils:6.16::el9
cpe:/a:redhat:satellite_utils:6.17::el9
cpe:/a:redhat:satellite_utils:6.18::el9
Vendors & Products Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
References

Fri, 29 Aug 2025 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title foreman: Satellite: GraphQL API permission bypass leads to information disclosure
Weaknesses CWE-200
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-02-27T07:28:44.391Z

Reserved: 2025-08-28T08:47:45.693Z

Link: CVE-2025-9572

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-27T08:17:06.373

Modified: 2026-02-27T14:06:37.987

Link: CVE-2025-9572

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-29T06:12:00Z

Links: CVE-2025-9572 - Bugzilla

cve-icon OpenCVE Enrichment

No data.