CVE-2026-12423: Red Hat Satellite
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
Affected products
- Red Hat Satellite: from 6.16, before 6.16.4 (fixed in 6.16.4); from 6.17, before 6.17.12 (fixed in 6.17.12); from 6.19, before 6.19.5 (fixed in 6.19.5); from 6.18, before 6.18.10 (fixed in 6.18.10); version 6.0 only
- Theforeman Foreman: affected versions not specified
Published 2026-10-01. Last modified 2026-10-08.