Bug 2489971 (CVE-2026-12542) - CVE-2026-12542 foreman: command injection in foreman-tail
Summary: CVE-2026-12542 foreman: command injection in foreman-tail
Keywords:
Status: NEW
Alias: CVE-2026-12542
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-17 16:48 UTC by OSIDB Bzimport
Modified: 2026-10-01 12:53 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-17 16:48:13 UTC
Description

The foreman-tail utility in Red Hat Satellite is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths. Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.

Impact

Successful exploitation allows a local attacker to escape restricted shells and execute arbitrary commands on the Satellite server. Consequently, the attacker could access sensitive information that could lead to remote code execution (RCE) and lateral movement across the managed infrastructure.

Recommendations

Refactor the script: Remove the use of eval. Use native shell array expansion or find to locate the necessary log files safely.

Input Validation: Implement a strict allow-list to ensure only valid service names are processed.


Note You need to log in before you can comment on or make changes to this bug.