Junglewise Threat Intelligence

CVE-2026-13316: Red Hat Foreman SSRF in http_proxies_controller

CVE-2026-13316 · Severity: medium · CVSS 4.4 · Published 2026-06-30

Vendors: Red Hat.

Executive brief

A security vulnerability has been identified in Foreman, a tool used for managing physical and virtual servers. An attacker with high-level access could manipulate internal settings to force the application to make unauthorized requests to cloud infrastructure services. In cloud environments like AWS, Azure, or GCP, this could allow the attacker to steal sensitive metadata and credentials, potentially leading to broader access to the organization's cloud environment.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability (CWE-918) exists in Foreman within the http_proxies_controller and http_proxy components. The flaw is triggered by unvalidated 'test_url' parameters in the Foreman configuration. An attacker with high privileges (PR:H) can modify these HTTP parameters to force the server to make requests to internal or restricted resources. In cloud-hosted environments, this is specifically exploitable to retrieve sensitive information from cloud metadata services (e.g., IMDSv1/v2). The vulnerability is tracked as CVE-2026-13316 and affects Red Hat Satellite 6 and standalone Foreman installations.

Affected products

  • Red Hat Foreman unspecified
  • Red Hat Red Hat Satellite 6 6

Timeline

  • 2026-06-18: disclosed: Initial report in Red Hat Bugzilla
  • 2026-06-30: advisory: NVD publication date

References