Junglewise Threat Intelligence

CVE-2026-92904: Red Hat Satellite foreman_remote_execution access control bypass in job invocations

CVE-2026-92904 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Vendors: Red Hat.

Executive brief

Red Hat Satellite's remote execution plugin fails to properly enforce permission checks when users view job invocation details. An authenticated user can bypass restrictions and read other users' job execution output, scripts, and input values within their organization. This exposes sensitive operational data that should only be accessible to authorized personnel, potentially revealing scripts, credentials, and system configurations.

Technical details

The vulnerability is an incorrect authorization (CWE-863) flaw in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action retrieves job invocation records by ID without enforcing the view_job_invocations permission filter, allowing permission-based access restrictions to be bypassed. An authenticated attacker with any view_job_invocations permission (included in default Remote Execution roles) can enumerate job invocation IDs and read live output, rendered scripts, and input values for other users' job invocations within the same organizations. The vulnerability was introduced in foreman_remote_execution version 15.0.0 when per-host job invocation detail view functionality was added; Red Hat Satellite 6.16 and earlier are unaffected. Host taxonomy default scope prevents cross-organization access, and template input flagged as hidden are masked.

Affected products

  • Red Hat Satellite 6.17, 6.18, 6.19
  • Red Hat foreman_remote_execution 15.0.0 and later

Timeline

  • 2026-09-17: disclosed
  • 2026-09-17: other: CVE-2026-92904 assigned

References