cbcvebase.
CVE-2026-5136
published 2026-07-01

CVE-2026-5136: A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an…

PriorityP262high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.30%
21.6th percentile
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.

Affected

7 ranges
VendorProductVersion rangeFixed in
redhatsatellite>= 6.16 < 6.16.106.16.10
redhatsatellite>= 6.17 < 6.17.96.17.9
redhatsatellite>= 6.18 < 6.18.76.18.7
redhatsatellite>= 6.19 < 6.19.26.19.2
satellite-capsule_el8foreman
theforemanforeman< 3.18.23.18.2
theforemanforeman>= 3.19.0 < 3.19.13.19.1

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for API requests (POST/PUT) to Foreman usergroup endpoints that include both a privileged role_id and a user_id belonging to the calling user — this is the single-request exploitation pattern.
  • Alert on authenticated Foreman users with create_usergroups or edit_usergroups permissions who assign administrative roles to a usergroup and simultaneously add themselves as a member.
  • Treat any non-admin account holding Site manager, Organization admin, Manager roles, or any custom role with create_usergroups/edit_usergroups as high-risk for this privilege escalation path.
  • ·The Usergroup model lacks the role-assignment escalation check that the User model enforces; patched versions are available in Red Hat Satellite 6.16 (RHSA-2026:34367), 6.17 (RHSA-2026:34366), and 6.18 (RHSA-2026:34368).
  • ·Affected package is satellite-capsule:el8/foreman shipped with Red Hat Satellite 6; ensure the foreman package is updated via the relevant RHSA advisory for your Satellite version.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.