Bug 2489992 (CVE-2026-12544) - CVE-2026-12544 foreman: SSTI and insecure deserialization in foreman-rake configuration
Summary: CVE-2026-12544 foreman: SSTI and insecure deserialization in foreman-rake con...
Keywords:
Status: NEW
Alias: CVE-2026-12544
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-17 17:03 UTC by OSIDB Bzimport
Modified: 2026-10-01 12:55 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-06-17 17:03:30 UTC
Description

The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a Multi-Stage Execution Chain that allows for both Server-Side Template Injection (SSTI) and Insecure Deserialization.

The vulnerability execution chain has two stages:

Template Injection (ERB): The first stage uses ERB.new(...).result. This evaluates the file as a Ruby template. Any code inside <%= ... %> is executed by the Ruby interpreter to generate a string. This is an SSTI that allows for direct OS command injection.

Insecure Deserialization (YAML): The second stage takes the rendered string and passes it to YAML.load. Because this is an unsafe parser, it allows for object injection. Even if an attacker cannot use ERB tags, they can craft YAML that instantiates malicious Ruby "gadget chains" to achieve code execution.

The vulnerability exists in two different application functionalities, thus it can be exploited in two different ways:

Primary config:

SETTINGS.merge! YAML.load(ERB.new(File.read(settings_file)).result) allows an attacker to craft a malicious /etc/foreman-maintain/foreman_maintain.yml file that will be loaded and executed by foreman-rake on start.

Plugins config:

SETTINGS.merge! YAML.load(ERB.new(File.read(f)).result) allows an attacker to craft a malicious file that will be executed from /usr/share/foreman/config/settings.plugins.d/ by foreman-rake on start.

Impact

Indirect Triggering & Privileged RCE: foreman-rake exposes underlying execution primitives that higher-level orchestration tools (like foreman-maintain or foreman-installer) rely on to interact with the application. Because these tools implicitly pass commands down, the vulnerability can be triggered indirectly during routine administrative operations, resulting in Remote Code Execution (RCE) in a high-trust context (often foreman or root).

Total Infrastructure Compromise: Compromising the management plane (Satellite server) allows an attacker to pivot and execute arbitrary code across all Satellite Managed Hosts.

Supply Chain Risk: While direct local exploitation requires prior root access, this flaw presents a critical supply chain risk. An adversary could distribute malicious plugins or compromised configuration files through public repositories (e.g., RubyGems, GitHub). Note: The CVSS vector and severity are based on this supply chain attack vector.

RECOMMENDATIONS

Replace YAML.load with YAML.safe_load(content, permitted_classes: [Symbol]) in both locations in settings.rb.

Remove the ERB.new().result evaluation. Configuration files must be treated as static data, never as executable templates.


Note You need to log in before you can comment on or make changes to this bug.