Project

General

Profile

Actions

Bug #39480

closed

CVE-2026-5135: Unauthorized modification of host configurations via broken access control

Added by Ondřej Gajdušek 16 days ago. Updated 16 days ago.

Status:
Closed
Priority:
Immediate
Assignee:
-
Category:
Security
Target version:
-

Description

A broken access control vulnerability was found in Foreman's handling of lookup value overrides. When lookup values are submitted as nested attributes during host or hostgroup updates, the match field is permitted and applied without ownership validation. A user with host-edit rights can retarget an existing lookup value override to point at a different host, injecting configuration values into hosts they are not authorized to edit. The injected values are served by the ENC/classification pipeline.

CVSS: 6.5 (Moderate)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE: CWE-639

Credit: Stanislav Fot (Aisle Research)

Actions #1

Updated by Ondřej Gajdušek 16 days ago

  • Private changed from Yes to No
Actions #2

Updated by The Foreman Bot 16 days ago

  • Status changed from New to Ready For Testing
  • Pull request https://github.com/theforeman/foreman/pull/11070 added
Actions #3

Updated by The Foreman Bot 16 days ago

  • Pull request https://github.com/theforeman/foreman/pull/11071 added
Actions #4

Updated by The Foreman Bot 16 days ago

  • Pull request https://github.com/theforeman/foreman/pull/11072 added
Actions #5

Updated by The Foreman Bot 16 days ago

  • Fixed in Releases 3.18.2 added
Actions #6

Updated by The Foreman Bot 16 days ago

  • Fixed in Releases 3.19.1 added
Actions #7

Updated by The Foreman Bot 16 days ago

  • Fixed in Releases 5.0.0 added
Actions #8

Updated by Lukáš Ježek 16 days ago

  • Status changed from Ready For Testing to Closed
Actions

Also available in: Atom PDF