Executive brief
A security flaw in Red Hat Satellite's foreman-mcp-server allows an attacker to take over active administrative sessions. By exploiting how the system manages user connections and logs sensitive session IDs, an unauthorized person could gain full administrative control over the infrastructure. This could lead to the theft of sensitive data or the execution of malicious commands across all managed systems.
Technical details
A session management vulnerability exists in the foreman-mcp-server's AuthMiddleware. The server improperly caches fully authenticated ForemanApi client connection objects in an in-memory dictionary keyed by a non-secret session ID (mcp-session-id). Because the server fails to re-validate the foreman_token on subsequent requests and logs new session IDs to standard logs at the INFO level, an attacker can harvest a session ID and hijack the connection. This allows the attacker to proxy JSON-RPC requests using the victim's Bearer token, leading to privilege escalation and infrastructure-wide remote code execution (RCE). The session remains valid until a server restart as there is no session termination mechanism.
Affected products
- Red Hat Satellite 6 satellite/foreman-mcp-server-rhel9
Timeline
- 2026-06-11: other: Initial report in Red Hat Bugzilla
- 2026-06-23: disclosed: CVE published to NVD