Bug 2490542 (CVE-2026-56098) - CVE-2026-56098 rubygem-katello: improper authorization logic allows resource enumeration
Summary: CVE-2026-56098 rubygem-katello: improper authorization logic allows resource ...
Keywords:
Status: NEW
Alias: CVE-2026-56098
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-18 18:57 UTC by OSIDB Bzimport
Modified: 2026-10-01 22:32 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:74504 0 None None None 2026-10-01 22:12:47 UTC
Red Hat Product Errata RHSA-2026:74505 0 None None None 2026-10-01 22:14:00 UTC
Red Hat Product Errata RHSA-2026:74506 0 None None None 2026-10-01 22:32:06 UTC

Description OSIDB Bzimport 2026-06-18 18:57:18 UTC
Description

The RegistryProxiesController in Katello contains an authorization bypass vulnerability due to an execution fall-through in the registry_authorize filter. While the application identifies unauthorized requests and triggers an error response via the unauthorized method, it fails to halt the execution of the current code path (missing return statement).

This failure in the control flow allows the application to proceed into subsequent business logic and database validation filters. Consequently, the application reveals its internal state through differential responses, allowing an unprivileged attacker to enumerate valid Users, Organizations, and Products across the entire instance.

--------------------------------------------------------------------------------

$ cat /usr/share/gems/gems/katello-4.20.0.rc1/app/controllers/katello/api/registry/registry_proxies_controller.rb

def registry_authorize

@repository = find_readable_repository

return true if ['GET', 'HEAD'].include?(request.method) && @repository && !require_user_authorization?

return true if authenticate_from_request(request.headers['Authorization'])

unauthorized [should be: “unauthorized and return”]

end

def unauthorized

redirect_authorization_headers

render_error('unauthorized', :status => :unauthorized)

false [no return here neither]

end

--------------------------------------------------------------------------------

Impact

User Enumeration: Attackers can verify the existence of usernames. Invalid users cause a server-side crash (500 Internal Server Error) because the fall-through logic cannot handle a null user object. Valid users trigger a semantic error (404 NAME_UNKNOWN), confirming their presence.

Resource Mapping: Unauthorized users can map hidden organizational structures. By observing the discrepancy between "Organization not found" and "Product not found", an attacker can confirm the existence of Organizations and Products they are explicitly forbidden from viewing.

Exploit Chain Enabler: This vulnerability provides the necessary "transport" for the F-38 SQL Injection in Registry Proxy via labels, allowing malicious payloads to reach the database layer despite failing initial authorization checks.

RECOMMENDATIONS



Fix Control Flow: Add an explicit “and return” to the unauthorized method call within registry_authorize to ensure the filter chain terminates immediately and prevents execution fall-through.

Normalize Error Responses: Configure the Registry API to return a uniform 401 Unauthorized response for all failed authorization attempts to eliminate the enumeration oracle.

Comment 2 Jon Orris 2026-10-01 22:12:45 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504

Comment 3 Jon Orris 2026-10-01 22:13:58 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505

Comment 4 Jon Orris 2026-10-01 22:32:05 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506


Note You need to log in before you can comment on or make changes to this bug.