Project

General

Profile

Actions

Bug #39478

closed

CVE-2026-5136: Privilege escalation via usergroup role assignment manipulation

Added by Ondřej Gajdušek about 1 month ago. Updated about 1 month ago.

Status:
Closed
Priority:
Immediate
Assignee:
-
Category:
Security
Target version:
-

Description

A privilege escalation vulnerability was found in Foreman's usergroup management. The Usergroup model does not validate whether the calling user is permitted to assign the specified roles, unlike the User model which enforces ensure_roles_not_escalated. A user with create_usergroups or edit_usergroups permission can attach arbitrary roles (including "System admin") to a usergroup via the API, add themselves as a member, and inherit those elevated privileges.

CVSS: 8.8 (Important)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE: CWE-266

Credit: Stanislav Fot (Aisle Research)

Actions #1

Updated by Ondřej Gajdušek about 1 month ago

  • Private changed from Yes to No
Actions #2

Updated by The Foreman Bot about 1 month ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/11064 added
Actions #3

Updated by The Foreman Bot about 1 month ago

  • Pull request https://github.com/theforeman/foreman/pull/11065 added
Actions #4

Updated by The Foreman Bot about 1 month ago

  • Pull request https://github.com/theforeman/foreman/pull/11066 added
Actions #5

Updated by The Foreman Bot about 1 month ago

  • Fixed in Releases 3.18.2 added
Actions #6

Updated by The Foreman Bot about 1 month ago

  • Fixed in Releases 3.19.1 added
Actions #7

Updated by The Foreman Bot about 1 month ago

  • Fixed in Releases 5.0.0 added
Actions #8

Updated by Lukáš Ježek about 1 month ago

  • Status changed from Ready For Testing to Closed
Actions

Also available in: Atom PDF