Junglewise Threat Intelligence

CVE-2026-5135: Foreman broken access control in host lookup value overrides

CVE-2026-5135 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: Foreman. Vendors: Foreman, Red Hat.

Executive brief

A security flaw has been identified in Foreman, a tool used to manage and automate the configuration of large-scale server environments. An authorized user with basic host-editing permissions could exploit this vulnerability to change configuration settings for servers they are not supposed to manage. This could lead to unauthorized changes in server behavior or security policies across different departments or locations within an organization.

Technical details

A broken access control vulnerability (CWE-639) exists in Foreman's handling of lookup value overrides. An authenticated attacker with 'edit_hosts' permissions can bypass authorization checks by modifying the 'match' field through nested host attributes. By first creating a legitimate override on a host they control and then retargeting the match field to a victim host's FQDN, the attacker can inject values into the ENC (External Node Classifier) pipeline. This allows for the unauthorized modification of managed host configurations across organizational and location boundaries, provided a lookup key with 'fqdn' in its path exists.

Affected products

  • Foreman Foreman
  • Red Hat Red Hat Satellite 6

Timeline

  • 2026-03-27: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-01: advisory: NVD publication date

References

Related threats