CVE-2018-14666: Red Hat Satellite

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions.

Affected products

  • Red Hat Satellite: from 6.0, up to and including 6.4

Published 2019-01-22. Last modified 2026-06-17.