Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution

Red Hat Satellite Foreman template preview authorization (TL-2026-2874) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-10-03. It has no confirmed attribution, affects Red Hat Red Hat Satellite, references 2 CVEs (CVE-2026-96659, CVE-2026-96658), maps to 6 MITRE ATT&CK techniques (T1005, T1059.004, T1078), and is covered by 9 detection rules and 7 indicators of compromise.

Key facts for TL-2026-2874

Threat ID
TL-2026-2874
Severity
CRITICAL
CVSS
9.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L)
Status
PATCHED
Category
VULNERABILITY
First published
2026-10-03
Last reviewed
2026-10-03
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, government administration, finance, telecoms, health
Target regions
Global
Detection rules
9
Indicators of compromise
7

Malware and tooling in Red Hat Satellite Foreman template preview authorization

Malware and tooling: Foreman Safemode

An authorization weakness (CWE-267) in Foreman template preview endpoints, used by Red Hat Satellite 6.16, 6.18 and 6.19, lets a low-privileged Viewer-role user with network access read admin-only data such as host root passwords, and potentially execute code as the foreman service account when Safemode protections are disabled. A related Safemode sandbox bypass leading to RCE is tracked as CVE-2026-96658 (CVSS 9.9). Patches were released and the flaw disclosed on 2026-10-01; no active exploitation or public PoC is reported.

How Red Hat Satellite Foreman template preview authorization works

CVE-2026-96659 is a flaw in Foreman, the provisioning and lifecycle component embedded in Red Hat Satellite. Red Hat describes it as excessive permissions granted to Viewer-role users on certain API endpoints, notably the template preview endpoint (/template/preview). An authenticated user holding only the low-privileged Viewer role can submit crafted requests to the template preview functionality and retrieve data that should be admin-only, including host root passwords. The weakness is classified as CWE-267 (Privilege Defined With Unsafe Actions; NVD labels it Improper Privilege Management). Red Hat scores it CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L = 9.1 (Red Hat product security rating: Important; NVD: Critical). Exploitation needs network access to the Satellite web/API interface and a valid Viewer account; no user interaction is required.

If Safemode protections for Foreman templates are disabled or bypassed, the same exposure can escalate to arbitrary command execution as the foreman system account. The Safemode bypass is tracked separately as CVE-2026-96658: an authenticated low-privileged attacker can achieve remote code execution by bypassing the safemode sandbox in the Foreman templating engine through improper handling of delegated methods (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H = 9.9, Red Hat Bugzilla 2534185). The Foreman templating sandbox has a history of such bypasses (for example CVE-2023-0118, an admin-user safe-mode bypass to OS code execution), so the two CVEs should be treated as a chained risk: credential disclosure plus a code-execution path on the provisioning server.

Impact is high because Satellite manages patching, provisioning and configuration for large RHEL fleets; exposed root passwords of managed hosts and code execution as the foreman account on the Satellite server can support lateral movement across the managed estate. Red Hat reported the issue on 2026-09-17 and shipped fixes on 2026-10-01. Fixed Foreman 3.12.0.23-1 is delivered via Satellite 6.16.14 (RHSA-2026:74506, RHEL 8 and 9); Satellite 6.18 is covered by RHSA-2026:74504 and 6.19 by RHSA-2026:74503 (RHEL 9). Red Hat's Bugzilla entry also lists Satellite 6.17 with RHSA-2026:74505, and NVD references all four advisories. The sources do not report in-the-wild exploitation, a public proof of concept, CISA KEV listing, attribution, or network IOCs. Recommended mitigations: apply the errata immediately, remove unnecessary Viewer-role accounts, verify Safemode remains enabled, and monitor template preview requests for abuse.

MITRE ATT&CK techniques used in TL-2026-2874

Collection

T1005 Data from Local System

Execution

T1059.004 Unix Shell

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Credential Access

T1212 Exploitation for Credential Access; T1552 Unsecured Credentials

Affected products and versions in Red Hat Satellite Foreman template preview authorization

  • Red Hat — Red Hat Satellite
    Vulnerable versions: 6.16 (RHEL 8, RHEL 9); 6.17 (RHEL 9, per Red Hat Bugzilla); 6.18 (RHEL 9); 6.19 (RHEL 9)
    Fixed in: 6.16.14 (Foreman 3.12.0.23-1); RHSA-2026:74504 (6.18); RHSA-2026:74503 (6.19); RHSA-2026:74505 (6.17)
  • Foreman Project — Foreman
    Vulnerable versions: Foreman builds shipped before 3.12.0.23 in Satellite 6.16
    Fixed in: 3.12.0.23-1

Remediation for Red Hat Satellite Foreman template preview authorization

Patches

  • Foreman 3.12.0.23-1 via Satellite 6.16.14 (RHEL 8 and RHEL 9)
  • Satellite 6.18 on RHEL 9: RHSA-2026:74504
  • Satellite 6.19 on RHEL 9: RHSA-2026:74503

Immediate actions

  • Apply Red Hat Satellite security errata RHSA-2026:74506 (6.16.14), RHSA-2026:74504 (6.18) and RHSA-2026:74503 (6.19) / RHSA-2026:74505 (6.17)
  • Review and remove unnecessary Viewer-role account access on Satellite
  • Verify Foreman Safemode protection remains enabled
  • Rotate host root passwords that may have been exposed through template preview

Workarounds

  • No dedicated workaround published; Red Hat advises upgrading to a fixed version or contacting Red Hat support

Longer-term hardening

  • Restrict network access to the Satellite web UI and API to management networks
  • Monitor and alert on template preview requests by low-privileged users
  • Apply least-privilege role design for Foreman/Satellite users

CVEs associated with Red Hat Satellite Foreman template preview authorization

CVE-2026-96659, CVE-2026-96658

Weaknesses (CWE) in Red Hat Satellite Foreman template preview authorization

CWE-267

Timeline of Red Hat Satellite Foreman template preview authorization

  • Earlier Foreman template safe-mode bypass CVE-2023-0118 (admin-level arbitrary code execution through templates) establishes the sandbox as a recurring weak point
  • Excessive Viewer-role permissions on Foreman template preview endpoints reported to Red Hat (Bugzilla 2536844)
  • CVE-2026-96659 (CVSS 9.1) and related Safemode bypass CVE-2026-96658 (CVSS 9.9) publicly disclosed and published to NVD
  • Red Hat releases Satellite errata RHSA-2026:74503, 74504, 74505 and 74506, including Satellite 6.16.14 with Foreman 3.12.0.23-1
  • Cyber Security News reports the flaw enabling root password theft and code execution on Red Hat Satellite
  • No in-the-wild exploitation, public PoC or CISA KEV listing reported in the reviewed sources

Sources cited for Red Hat Satellite Foreman template preview authorization

More in vulnerability

Detection coverage for TL-2026-2874

As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2874 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats