← Back

CVE-2025-9572

nvd nist
Published: Feb 27, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

Affected (10)

1 product
Foreman
3 products
Enterprise Linux
Satellite
Satellite Capsule
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 1.22.0 to 3.16.2
Configuration B
9 vulnerable
Vulnerable SoftwareAffected Versions
Version 9.0
Redhat
Version 6.15
Version 6.16
Version 6.17
Version 6.18
Redhat
Version 6.15
Version 6.16
Version 6.17
Version 6.18

References (7)

Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue Tracking
Source: secalert@redhat.com
Vendor Advisory

Timeline

No history available yet.