Bug 2489970 (CVE-2026-12541) - CVE-2026-12541 foreman: command injection in foreman-rake database tasks
Summary: CVE-2026-12541 foreman: command injection in foreman-rake database tasks
Keywords:
Status: NEW
Alias: CVE-2026-12541
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-17 16:46 UTC by OSIDB Bzimport
Modified: 2026-10-01 12:50 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-17 16:46:21 UTC
Description

OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks within Red Hat Satellite (Foreman). The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution.

An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.

Impact

Exploitation allows a restricted user to escalate privileges to the foreman account and execute arbitrary commands . This grants control over the Satellite database and configurations, enabling lateral movement and full root Remote Code Execution on all managed hosts (as demonstrated in F-03 Command Injection in foreman-rake errors:fetch_log via request_id Parameter).

Recommendations

Validate Input: Implement strict validation for both the destination and file parameters in the Rake tasks to ensure they only contain valid filesystem paths and no shell metacharacters before processing.

Use Argument Arrays: Modify the underlying code to use non-shell execution methods (e.g., passing arguments as an array to system() or exec()) to prevent shell interpretation.


Note You need to log in before you can comment on or make changes to this bug.