Junglewise Threat Intelligence

CVE-2026-92894: Red Hat foreman_ansible authorization bypass in LookupValue deletion

CVE-2026-92894 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Vendors: Red Hat.

Executive brief

The foreman_ansible plugin, used in Red Hat Satellite to manage Ansible configuration overrides, contains an authorization flaw in its API destroy action. An authenticated user with edit_ansible_variables permission can delete configuration values (LookupValues) for Ansible variables and Puppet parameters they are not authorized to manage, leading to unintended modification or loss of configuration data that can disrupt infrastructure management.

Technical details

The vulnerability is an incorrect authorization (CWE-863) in the foreman_ansible plugin's override values controller. The destroy action resolves and deletes LookupValue records by ID without verifying the record belongs to an AnsibleVariable the caller is authorized to edit, and without validating the model type (AnsibleVariable vs. PuppetclassLookupKey). An authenticated user with the edit_ansible_variables permission can therefore delete any LookupValue, bypassing both the permission's search filter scope and the model type boundary. The vulnerability is network-reachable and requires low-privilege authentication; the create and update actions in the same controller correctly validate authorization, indicating this is an oversight. The impact is limited to integrity (unauthorized deletion of configuration data), which is recoverable; no confidentiality or availability impact exists.

Affected products

  • Red Hat Satellite <UNKNOWN>

Timeline

  • 2026-09-17: disclosed

References