CVE-2026-12112
published 2026-06-23CVE-2026-12112: A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active…
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.15%
4.9th percentile
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | — | — |
| satellite | foreman-mcp-server-rhel9 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
foreman-mcp-server: MCP Server: Active Session Hijacking via Insecure Session State Reuse
vendor_redhat·2026-06-23·CVSS 7.8
CVE-2026-12112 [HIGH] CWE-287 foreman-mcp-server: MCP Server: Active Session Hijacking via Insecure Session State Reuse
foreman-mcp-server: MCP Server: Active Session Hijacking via Insecure Session State Reuse
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.
Statement: Success exploitation leads to privilege escalation, granting an unauthenticated attacker the ability to execute infrastructure-wide code execution. Due to this reason, this flaw has been rated with an important severity.
Mitigation: R
GHSA
A flaw was found in the foreman-mcp-server.
ghsa_unreviewed·2026-06-23
CVE-2026-12112 [HIGH] CWE-287 A flaw was found in the foreman-mcp-server.
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2026:28405https://access.redhat.com/errata/RHSA-2026:28438https://access.redhat.com/security/cve/CVE-2026-12112https://bugzilla.redhat.com/show_bug.cgi?id=2488031https://access.redhat.com/errata/RHSA-2026:28405https://access.redhat.com/errata/RHSA-2026:28438https://access.redhat.com/security/cve/CVE-2026-12112https://bugzilla.redhat.com/show_bug.cgi?id=2488031https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12112.json
2026-06-23
Published