Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL. | |
| Title | Foreman: unauthenticated information disclosure via provisioning token validation flaw | |
| First Time appeared |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:satellite:6 cpe:/a:redhat:satellite:6.19::el9 cpe:/a:redhat:satellite_capsule:6.19::el9 cpe:/a:redhat:satellite_utils:6.19::el9 |
|
| Vendors & Products |
Redhat
Redhat satellite Redhat satellite Capsule Redhat satellite Utils |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-01T17:36:27.434Z
Reserved: 2026-06-16T16:57:36.339Z
Link: CVE-2026-12423
Updated: 2026-10-01T17:36:24.766Z
Status : Received
Published: 2026-10-01T17:17:19.887
Modified: 2026-10-01T18:17:14.853
Link: CVE-2026-12423
No data.
OpenCVE Enrichment
Updated: 2026-10-01T18:00:08Z