Description
A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user.
Title Rubygem-foreman_remote_execution: command injection in job invocations via effective_user parameter
First Time appeared Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
Weaknesses CWE-78
CPEs cpe:/a:redhat:satellite:6
cpe:/a:redhat:satellite:6.19::el9
cpe:/a:redhat:satellite_capsule:6.19::el9
cpe:/a:redhat:satellite_utils:6.19::el9
Vendors & Products Redhat
Redhat satellite
Redhat satellite Capsule
Redhat satellite Utils
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Satellite Satellite Capsule Satellite Utils
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-10-01T18:01:19.957Z

Reserved: 2026-06-16T13:54:29.597Z

Link: CVE-2026-12405

cve-icon Vulnrichment

Updated: 2026-10-01T18:01:08.531Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T17:17:19.717

Modified: 2026-10-01T20:36:15.187

Link: CVE-2026-12405

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T18:00:08Z

Weaknesses