← Back

CVE-2026-5136

nvd nist
Published: Jul 1, 2026Modified: Jul 9, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: secalert@redhat.com (Secondary)

Description

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.

Affected (6)

1 product
Satellite
1 product
Foreman
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 6.16 to 6.16.10
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.17 to 6.17.9
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
From 6.18 to 6.18.7
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 6.19 to 6.19.2
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 9.0
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Theforeman
Before 3.18.2
From 3.19.0 to 3.19.1

References (6)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.