CVE-2026-1531: Red Hat Satellite 6
High severity, CVSS 8.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A flaw was found in foreman_kubevirt. When configuring the connection to OpenShift, the system disables SSL verification if a Certificate Authority (CA) certificate is not explicitly set. This insecure default allows a remote attacker, capable of intercepting network traffic between Satellite and OpenShift, to perform a Man-in-the-Middle (MITM) attack. Such an attack could lead to the disclosure or alteration of sensitive information.
Affected products
- Red Hat Red Hat Satellite 6
- Red Hat Red Hat Satellite 6.16 For Rhel 8: before 0:0.2.0-2.el8sat (fixed in 0:0.2.0-2.el8sat)
- Red Hat Red Hat Satellite 6.16 For Rhel 9: before 0:0.2.0-2.el9sat (fixed in 0:0.2.0-2.el9sat)
- Red Hat Red Hat Satellite 6.17 For Rhel 9: before 0:3.14.0.14-1.el9sat (fixed in 0:3.14.0.14-1.el9sat); before 0:0.1.23-0.3.el9pc (fixed in 0:0.1.23-0.3.el9pc); before 0:1.2.0-0.1.el9pc (fixed in 0:1.2.0-0.1.el9pc); before 0:4.2.28-0.1.el9pc (fixed in 0:4.2.28-0.1.el9pc); before 0:2.22.3-1.el9pc (fixed in 0:2.22.3-1.el9pc); before 0:3.27.10-2.el9pc (fixed in 0:3.27.10-2.el9pc); …
- Red Hat Red Hat Satellite 6.18 For Rhel 9: before 0:0.4.3-1.el9sat (fixed in 0:0.4.3-1.el9sat)
Published 2026-02-02. Last modified 2026-07-15.