Threat Advisory

Red Hat Satellite Flaw Exposes Host Root Passwords to Low-Privileged Users

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information, including root passwords. Under unsafe configurations, the flaws could also escalate to arbitrary command execution as the Foreman service account. The affected version range is not explicitly stated in the article.

CVE-2026-96659 (CVSS 9.1 — Important): A low-privileged authenticated user can access sensitive host information, including root passwords, through an authorization weakness in Foreman template preview endpoints. This may include host root passwords, creating a serious risk for organizations that use Satellite to provision or manage large fleets of Red Hat Enterprise Linux systems.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information, including root passwords. Under unsafe configurations, the flaws could also escalate to arbitrary command execution as the Foreman service account. The affected version range is not explicitly stated in the article.

CVE-2026-96659 (CVSS 9.1 — Important): A low-privileged authenticated user can access sensitive host information, including root passwords, through an authorization weakness in Foreman template preview endpoints. This may include host root passwords, creating a serious risk for organizations that use Satellite to provision or manage large fleets of Red Hat Enterprise Linux systems.[emaillocker id="1283"]

CVE-2026-96658 (CVSS X.X — Severity): A separate Foreman Safemode bypass flaw can lead to remote code execution. Organizations should treat these related Foreman security issues as a priority patching event rather than addressing CVE-2026-96659 in isolation.

RECOMMENDATION:

We recommend you to update Red Hat Satellite to version 3.12.0.23-1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu