Project

General

Profile

Actions

Bug #39480

closed

CVE-2026-5135: Unauthorized modification of host configurations via broken access control

Added by Ondřej Gajdušek about 1 month ago. Updated about 1 month ago.

Status:
Closed
Priority:
Immediate
Assignee:
-
Category:
Security
Target version:
-

Description

A broken access control vulnerability was found in Foreman's handling of lookup value overrides. When lookup values are submitted as nested attributes during host or hostgroup updates, the match field is permitted and applied without ownership validation. A user with host-edit rights can retarget an existing lookup value override to point at a different host, injecting configuration values into hosts they are not authorized to edit. The injected values are served by the ENC/classification pipeline.

CVSS: 6.5 (Moderate)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CWE: CWE-639

Credit: Stanislav Fot (Aisle Research)

Actions

Also available in: Atom PDF