CVE-2026-5142
published 2026-07-01CVE-2026-5142: A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.25%
16.6th percentile
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | satellite | >= 6.16 < 6.16.10 | 6.16.10 |
| redhat | satellite | >= 6.17 < 6.17.9 | 6.17.9 |
| redhat | satellite | >= 6.18 < 6.18.7 | 6.18.7 |
| redhat | satellite | >= 6.19 < 6.19.2 | 6.19.2 |
| satellite-capsule_el8 | foreman | — | — |
| theforeman | foreman | < 3.18.2 | 3.18.2 |
| theforeman | foreman | >= 3.19.0 < 3.19.1 | 3.19.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A flaw was found in foreman.
ghsa_unreviewed·2026-07-01
CVE-2026-5142 [MEDIUM] CWE-639 A flaw was found in foreman.
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Red Hat
foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass
vendor_redhat·2026-04-30·CVSS 6.5
CVE-2026-5142 [MEDIUM] CWE-639 foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass
foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.
Package: satellite-capsule:el8/foreman (Red Hat Satellite 6) - Affected
No detection rules found.
No public exploits indexed.
2026-07-01
Published