CVE-2026-12544: Red Hat Satellite

High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.

Affected products

  • Red Hat Satellite: version 6.0 only; from 6.16, before 6.16.4 (fixed in 6.16.4); from 6.17, before 6.17.12 (fixed in 6.17.12); from 6.19, before 6.19.5 (fixed in 6.19.5); from 6.18, before 6.18.10 (fixed in 6.18.10)
  • Theforeman Foreman: affected versions not specified

Published 2026-10-01. Last modified 2026-10-08.