Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths. | |
| Title | Foreman: command injection in foreman-rake database tasks | |
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:satellite:6 cpe:/a:redhat:satellite:6.19::el9 cpe:/a:redhat:satellite_capsule:6.19::el9 cpe:/a:redhat:satellite_utils:6.19::el9 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-01T16:34:36.766Z
Reserved: 2026-06-17T17:41:21.684Z
Link: CVE-2026-12541
No data.
Status : Received
Published: 2026-10-01T17:17:20.190
Modified: 2026-10-01T17:17:20.190
Link: CVE-2026-12541
No data.
OpenCVE Enrichment
Updated: 2026-10-01T17:30:10Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')