Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81658— Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup

Quick assessment

Affected
Red Hat Red Hat Satellite 6
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Foreman 中存在一个缺陷:模板修订端点(template revision endpoint)在检索经过审计的模板修订记录时,未强制实施对象级授权。一个拥有模板相关权限(如 )的低权限认证用户,可以通过提供相应的审计 ID,获取属于其他组织或位置的历史模板内容。这可能导致未经授权披露历史模板内容,其中可能包含敏感的配置文件信息、凭据或其他机密信息。REST API 的修订端点对此查找操作有正确的限制。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81658

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Satellite 6 - cpe:/a:redhat:satellite:6

II. Public POCs for CVE-2026-81658

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81658

登录查看更多情报信息。

Other References for CVE-2026-81658 (1)

Same Patch Batch · Red Hat · 2026-08-27 · 4 CVEs total

CVE-2026-5680 7.5 HIGH Undertow-core: undertow: denial of service via websocket permessage-deflate processing
CVE-2026-78002 7.5 HIGH Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() fun
CVE-2026-81668 5.4 MEDIUM Rubygem-katello: cross-tenant content view filter rule access and modification via unautho

IV. Related Vulnerabilities

V. Comments for CVE-2026-81658

No comments yet


Leave a comment