Junglewise Threat Intelligence

CVE-2026-5136: Foreman privilege escalation in Usergroup model

CVE-2026-5136 · Severity: high · CVSS 8.8 · Published 2026-07-01

Technologies: Foreman. Vendors: Red Hat, Foreman.

Executive brief

A security flaw in Foreman, a tool used for managing physical and virtual servers, allows users with limited management rights to grant themselves full administrative control. By exploiting a weakness in how the system handles user groups, an attacker can assign high-level permissions to themselves that they should not have access to. This could result in a complete takeover of the server management infrastructure, potentially leading to unauthorized data access or service disruption across the entire network.

Technical details

A privilege escalation vulnerability exists in Foreman due to improper validation in the Usergroup model. Unlike the User model, the Usergroup model fails to verify if the calling user has the authority to assign specific roles. An authenticated attacker with 'create_usergroups' or 'edit_usergroups' permissions can submit a crafted API request to attach arbitrary roles (including administrative ones) to a user group and then add themselves as a member. This bypasses standard escalation checks, granting the attacker full administrator-level access to the Foreman instance.

Affected products

  • Foreman Foreman unspecified
  • Red Hat Red Hat Satellite 6 6

Timeline

  • 2026-03-30: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-01: advisory: NVD publication date

References

Related threats