Bug 2489969 (CVE-2026-12540)

Summary: CVE-2026-12540 foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anthomas, ehelms, ggainey, jpasqual, juwatts, mdellweg, mhulan, nmoumoul, osousa, pcreech, rchan, security-response-team, smallamp, tmalecek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Deadline: 2026-10-01   

Description OSIDB Bzimport 2026-06-17 16:44:10 UTC
Description

A command injection vulnerability exists in the foreman-rake errors:fetch_log task within Red Hat Satellite. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.

Impact

Successful exploitation allows a restricted user to escalate privileges to the foreman user and subsequently to root across all managed hosts, Organizations, and Locations. This represents a complete compromise of the Red Hat Satellite server and the entire infrastructure it manages.

Recommendations

Validate Input: Sanitize the request_id parameter to ensure it only contains alphanumeric characters and dashes, rejecting any input containing shell metacharacters.

Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation (e.g., using Open3.capture3 with separate arguments in Ruby). Specifically, the following code in lib/tasks/errors.rake file should be replaced with something like this:

--------------------------------------------------------------------------------

// Vulnerable code

result = `grep "#{request_id}" "#{file_path}"`

Comment 2 Jon Orris 2026-10-01 22:11:52 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504

Comment 3 Jon Orris 2026-10-01 22:14:07 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505

Comment 4 Jon Orris 2026-10-01 22:31:55 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506