Junglewise Threat Intelligence

CVE-2026-5142: Foreman authorization bypass in KeyPairsController taxonomy scoping

CVE-2026-5142 · Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: The Foreman Project Foreman. Vendors: Red Hat.

Executive brief

A security flaw in the Foreman infrastructure management tool allows authorized users to access and download private SSH keys belonging to other organizations or tenants. In multi-tenant environments, this could lead to unauthorized access to remote servers and the exposure of sensitive credentials. An attacker only needs basic viewing permissions within their own organization to exploit this weakness and access data from others.

Technical details

A vulnerability exists in the KeyPairsController#show component of Foreman due to improper taxonomy scoping. Authenticated users with the 'view_keypairs' permission (such as those with a 'Viewer' role) can bypass organizational boundaries by directly querying specific KeyPair IDs. Because these IDs are often predictable or enumerable, an attacker can perform cross-tenant data extraction to obtain private SSH keys. This issue affects multi-tenant deployments where data isolation between organizations is required. The vulnerability is tracked as CWE-639 (Insecure Direct Object Reference).

Affected products

  • The Foreman Project Foreman
  • Red Hat Satellite 6

Timeline

  • 2026-03-30: disclosed: Initial report in Red Hat Bugzilla
  • 2026-07-01: advisory: CVE published and NVD record created

References