Junglewise Threat Intelligence

CVE-2026-5138: Foreman information disclosure via improper validation in taxonomy_scope

CVE-2026-5138 · Severity: medium · CVSS 4.3 · Published 2026-07-01

Technologies: Foreman. Vendors: Red Hat, Foreman.

Executive brief

Foreman, a tool used for managing physical and virtual servers, contains a security flaw that allows authorized users to view information they should not have access to. An attacker with basic host-editing permissions can bypass security boundaries to view sensitive network details from other organizations or departments managed on the same system. This could expose private infrastructure data such as IP ranges, DNS server addresses, and internal network layouts.

Technical details

A vulnerability exists in Foreman's taxonomy_scope controller method due to improper validation of organization and location IDs within nested request parameters. While top-level parameters may be validated, the application fails to verify that nested IDs belong to the user's authorized taxonomy memberships, effectively bypassing the set_taxonomy authorization check. An attacker with 'create_hosts' or 'edit_hosts' permissions can craft a malicious HTTP request containing a foreign organization ID in the nested parameters to leak metadata including subnet topology, IP ranges, gateways, DNS servers, and VLAN IDs. This affects Foreman and Red Hat Satellite 6 environments.

Affected products

  • Foreman Foreman unspecified
  • Red Hat Red Hat Satellite 6 6

Timeline

  • 2026-03-30: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-01: advisory: NVD and Red Hat published advisory details

References

Related threats