Junglewise Threat Intelligence

CVE-2025-58713: Red Hat Process Automation Manager privilege escalation in container images

CVE-2025-58713 · Severity: medium · CVSS 6.4 · Published 2026-04-08

Vendors: Redhat, Red Hat.

Executive brief

A security flaw in certain Red Hat Process Automation Manager container images could allow a user with limited access to gain full administrative (root) control over the container. This occurs because a critical system file was incorrectly configured with excessive permissions during the manufacturing of the software image. If an attacker can run commands inside the container, they could modify system settings to grant themselves unrestricted access, potentially compromising the application and its data.

Technical details

A privilege escalation vulnerability exists in Red Hat Process Automation Manager 7 container images due to incorrect default permissions (CWE-276). The /etc/passwd file is created with group-writable permissions during the image build process. An attacker who has already gained the ability to execute commands within the container and is a member of the root group can modify /etc/passwd to add a new user with UID 0. This allows for a full transition from a non-privileged user to root within the container environment. The attack requires local access and high privileges (membership in the root group) to execute.

Affected products

  • Red Hat Process Automation Manager 7 7.0

Timeline

  • 2025-09-10: other: Initial report in Red Hat Bugzilla
  • 2026-04-08: disclosed: Vulnerability disclosed and CVE published

References