Bug 2488956 (CVE-2026-12423)

Summary: CVE-2026-12423 foreman: unauthenticated information disclosure via provisioning token validation flaw
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anthomas, ehelms, ggainey, jpasqual, juwatts, mdellweg, mhulan, nmoumoul, osousa, pcreech, rchan, security-response-team, smallamp, tmalecek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-10-01   

Description OSIDB Bzimport 2026-06-15 17:59:08 UTC
Description

The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. 

Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. 

-------------------------------------------------------------------------------- 

/usr/share/foreman/app/services/foreman/unattended_installation/host_verifier.rb 

def valid_host_token? 

return true unless @needs_token 

return true unless for_host_template 

VULNERABILITY: This only checks if the token in the database is currently expired. 

It does NOT verify if the requester actually provided a valid token in the URL. 

return true unless @host&.token_expired? 

errors << { ... } 

false 

end 

-------------------------------------------------------------------------------- 

Impact

By utilizing the enumeration technique detailed in F-26 Infrastructure Mapping via Observable Response Discrepancy, an unauthenticated remote attacker can actively poll the endpoint for a host entering a build state and extract its complete provisioning template. These templates contain highly sensitive data, including the root user's SHA-512 password hash, internal IP topography, and active API build tokens.

Comment 2 Jon Orris 2026-10-01 22:11:48 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504

Comment 3 Jon Orris 2026-10-01 22:14:10 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505

Comment 4 Jon Orris 2026-10-01 22:31:53 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506