Project

General

Profile

Actions

Bug #39478

closed

CVE-2026-5136: Privilege escalation via usergroup role assignment manipulation

Added by Ondřej Gajdušek 16 days ago. Updated 16 days ago.

Status:
Closed
Priority:
Immediate
Assignee:
-
Category:
Security
Target version:
-

Description

A privilege escalation vulnerability was found in Foreman's usergroup management. The Usergroup model does not validate whether the calling user is permitted to assign the specified roles, unlike the User model which enforces ensure_roles_not_escalated. A user with create_usergroups or edit_usergroups permission can attach arbitrary roles (including "System admin") to a usergroup via the API, add themselves as a member, and inherit those elevated privileges.

CVSS: 8.8 (Important)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE: CWE-266

Credit: Stanislav Fot (Aisle Research)

Actions #1

Updated by Ondřej Gajdušek 16 days ago

  • Private changed from Yes to No
Actions #2

Updated by The Foreman Bot 16 days ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/11064 added
Actions #3

Updated by The Foreman Bot 16 days ago

  • Pull request https://github.com/theforeman/foreman/pull/11065 added
Actions #4

Updated by The Foreman Bot 16 days ago

  • Pull request https://github.com/theforeman/foreman/pull/11066 added
Actions #5

Updated by The Foreman Bot 16 days ago

  • Fixed in Releases 3.18.2 added
Actions #6

Updated by The Foreman Bot 16 days ago

  • Fixed in Releases 3.19.1 added
Actions #7

Updated by The Foreman Bot 16 days ago

  • Fixed in Releases 5.0.0 added
Actions #8

Updated by Lukáš Ježek 16 days ago

  • Status changed from Ready For Testing to Closed
Actions

Also available in: Atom PDF