Bug 2489969 (CVE-2026-12540) - CVE-2026-12540 foreman: command injection in foreman-rake errors:fetch_log via request_id parameter
Summary: CVE-2026-12540 foreman: command injection in foreman-rake errors:fetch_log vi...
Keywords:
Status: NEW
Alias: CVE-2026-12540
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-17 16:44 UTC by OSIDB Bzimport
Modified: 2026-10-01 12:47 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-17 16:44:10 UTC
Description

A command injection vulnerability exists in the foreman-rake errors:fetch_log task within Red Hat Satellite. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.

Impact

Successful exploitation allows a restricted user to escalate privileges to the foreman user and subsequently to root across all managed hosts, Organizations, and Locations. This represents a complete compromise of the Red Hat Satellite server and the entire infrastructure it manages.

Recommendations

Validate Input: Sanitize the request_id parameter to ensure it only contains alphanumeric characters and dashes, rejecting any input containing shell metacharacters.

Use Argument Arrays: Replace system calls that use shell string interpolation with array-based arguments to prevent shell interpretation (e.g., using Open3.capture3 with separate arguments in Ruby). Specifically, the following code in lib/tasks/errors.rake file should be replaced with something like this:

--------------------------------------------------------------------------------

// Vulnerable code

result = `grep "#{request_id}" "#{file_path}"`


Note You need to log in before you can comment on or make changes to this bug.