Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 01 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user. | |
| Title | Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter | |
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:satellite:6 cpe:/a:redhat:satellite:6.19::el9 cpe:/a:redhat:satellite_capsule:6.19::el9 cpe:/a:redhat:satellite_utils:6.19::el9 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-01T18:01:19.957Z
Reserved: 2026-06-16T13:54:29.597Z
Link: CVE-2026-12405
Updated: 2026-10-01T18:01:08.531Z
Status : Received
Published: 2026-10-01T17:17:19.717
Modified: 2026-10-01T19:17:19.643
Link: CVE-2026-12405
No data.
OpenCVE Enrichment
Updated: 2026-10-01T18:00:08Z
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')