Bug 2488956 (CVE-2026-12423) - CVE-2026-12423 foreman: unauthenticated information disclosure via provisioning token validation flaw
Summary: CVE-2026-12423 foreman: unauthenticated information disclosure via provisioni...
Keywords:
Status: NEW
Alias: CVE-2026-12423
Deadline: 2026-10-01
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-15 17:59 UTC by OSIDB Bzimport
Modified: 2026-10-01 22:31 UTC (History)
14 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:74504 0 None None None 2026-10-01 22:11:49 UTC
Red Hat Product Errata RHSA-2026:74505 0 None None None 2026-10-01 22:14:11 UTC
Red Hat Product Errata RHSA-2026:74506 0 None None None 2026-10-01 22:31:55 UTC

Description OSIDB Bzimport 2026-06-15 17:59:08 UTC
Description

The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. 

Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. 

-------------------------------------------------------------------------------- 

/usr/share/foreman/app/services/foreman/unattended_installation/host_verifier.rb 

def valid_host_token? 

return true unless @needs_token 

return true unless for_host_template 

VULNERABILITY: This only checks if the token in the database is currently expired. 

It does NOT verify if the requester actually provided a valid token in the URL. 

return true unless @host&.token_expired? 

errors << { ... } 

false 

end 

-------------------------------------------------------------------------------- 

Impact

By utilizing the enumeration technique detailed in F-26 Infrastructure Mapping via Observable Response Discrepancy, an unauthenticated remote attacker can actively poll the endpoint for a host entering a build state and extract its complete provisioning template. These templates contain highly sensitive data, including the root user's SHA-512 password hash, internal IP topography, and active API build tokens.

Comment 2 Jon Orris 2026-10-01 22:11:48 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.18 for RHEL 9

Via RHSA-2026:74504 https://access.redhat.com/errata/RHSA-2026:74504

Comment 3 Jon Orris 2026-10-01 22:14:10 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.17 for RHEL 9

Via RHSA-2026:74505 https://access.redhat.com/errata/RHSA-2026:74505

Comment 4 Jon Orris 2026-10-01 22:31:53 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:74506 https://access.redhat.com/errata/RHSA-2026:74506


Note You need to log in before you can comment on or make changes to this bug.