8

CVE-2026-1961

Forman: foreman: remote code execution via command injection in websocket proxy

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerRed Hat
Produkt Red Hat Satellite 6.16 for RHEL 8
Default Statusaffected
Version 0:3.12.0.14-1.el8sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.16 for RHEL 9
Default Statusaffected
Version 0:3.12.0.14-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:3.14.0.14-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.1.23-0.3.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:1.2.0-0.1.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:4.2.28-0.1.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:2.22.3-1.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:3.27.10-2.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:1.5.1-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.4.3-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:4.16.0.14-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.13.0-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:6.17.7-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.0.3-4.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:3.14.0.14-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.1.23-0.3.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:1.2.0-0.1.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:4.2.28-0.1.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:2.22.3-1.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:3.27.10-2.el9pc
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:1.5.1-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.4.3-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:4.16.0.14-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.13.0-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:6.17.7-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.17 for RHEL 9
Default Statusaffected
Version 0:0.0.3-4.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6.18 for RHEL 9
Default Statusaffected
Version 0:3.16.0.12-1.el9sat
Version < *
Status unaffected
HerstellerRed Hat
Produkt Red Hat Satellite 6
Default Statusaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.136
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
secalert@redhat.com 8 2.1 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.