Byc editing the CoreOS Transpiler Command in Provisioning Settings with "/bin/bash,/dev/stdin" value, and filling a template body within the template renderer with a command payload, an attacker with admin privileges on the foreman instance can execute arbitrary code on the underlying operating system.
*** This bug has been marked as a duplicate of bug 2140577 ***