Executive brief
Red Hat Satellite is a management platform used to deploy and manage infrastructure. A security flaw in its Katello component allows an authenticated user with limited permissions to check for the existence of software content in repositories they are not authorized to access. While this does not allow an attacker to modify or delete data, it results in an unauthorized disclosure of information regarding what software is present on the system.
Technical details
A missing object-level authorization check was identified in Katello's ContentUploadsController. The vulnerability exists because the controller does not enforce product-scoped authorization on the repository_id parameter. An authenticated attacker with 'edit_products' permissions for a specific subset of products can call the /katello/api/v2/repositories/:id/content_uploads endpoint against repositories outside their authorized scope. This allows the attacker to perform an information disclosure attack to determine if specific content exists in restricted repositories, though it does not permit modification, import, or publication of that content.
Affected products
- Red Hat Red Hat Satellite 6 6.x
- Katello Katello
Timeline
- 2026-04-16: patched: Fix submitted via GitHub pull request 11712
- 2026-06-17: disclosed: Initial vulnerability report and CVE assignment