Fedora Account System
Red Hat Associate
Red Hat Customer
Summary: A privilege escalation flaw was found in Foreman. The Usergroup model does not validate role assignments against the calling user's permissions, unlike the User model which enforces escalation checks. This flaw allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and add themselves as a member, resulting in full privilege escalation to administrator-level access. Requirements to exploit: Authenticated Foreman account with create_usergroups or edit_usergroups permission (e.g., Site manager, Organization admin, Manager roles, or any custom role including these permissions). Attacker crafts a single API request to create or update a user group with a privileged role_id and their own user_id.
This issue has been addressed in the following products: Red Hat Satellite 6.17 for RHEL 9 Via RHSA-2026:34366 https://access.redhat.com/errata/RHSA-2026:34366
This issue has been addressed in the following products: Red Hat Satellite 6.18 for RHEL 9 Via RHSA-2026:34368 https://access.redhat.com/errata/RHSA-2026:34368
This issue has been addressed in the following products: Red Hat Satellite 6.16 for RHEL 8 Red Hat Satellite 6.16 for RHEL 9 Via RHSA-2026:34367 https://access.redhat.com/errata/RHSA-2026:34367