securityonline.info 2 Oct 2026, 02:29 UTC

Critical Foreman Flaws Put Red Hat Satellite Deployments at Risk

Critical Foreman Flaws Put Red Hat Satellite Deployments at Risk
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

RED Hat has disclosed a critical set of Foreman flaws that affect Red Hat Satellite deployments and, in the case of 389-ds-base, LDAP clients. The most severe bug, CVE-2026-96658, enables an authenticated user with minimal permissions to achieve remote code execution by escaping the Foreman safemode sandbox and adding unauthorized functions to the allowed list.

A second Foreman issue, CVE-2026-96659, can let a user with Viewer rights query template preview endpoints and potentially access sensitive data such as host root passwords; if safemode is disabled, this path can also expose an RCE vector. A third flaw, CVE-2026-86345, resides in 389-ds-base and concerns StartTLS handling, where plaintext data buffered during an upgrade could be exploited in a man-in-the-middle position to cause a mis-login to appear successful. All three flaws are rated high-severity (9.9, 9.1, and 9.0 respectively).

Evidence and practical response are limited to advisory notes: there is no confirmed exploitation reported in the wild at the time of the article, and Red Hat has released patches. Affected Red Hat Satellite deployments using Foreman should apply updates as they ship to versions 0:1.5.0-2.el8sat, 0:1.5.0-2.el9sat, 0:3.18.0[.]14-1.el9sat, and 0:3.12.0[.]23-1.el8sat (+2).

Additional mitigations include keeping safemode enabled in Foreman, trimming Viewer-role assignments, and for the LDAP issue disable StartTLS on port 389 while preferring ldaps on port 636.

View full article

Article by CyberSIXT