CVE-2026-12541: Red Hat Satellite

High severity, CVSS 8.2. EPSS: 1.2% chance of exploitation in the next 30 days.

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Affected products

  • Red Hat Satellite: version 6.0 only; from 6.16, before 6.16.4 (fixed in 6.16.4); from 6.17, before 6.17.12 (fixed in 6.17.12); from 6.19, before 6.19.5 (fixed in 6.19.5); from 6.18, before 6.18.10 (fixed in 6.18.10)
  • Theforeman Foreman: affected versions not specified

Published 2026-10-01. Last modified 2026-10-08.