Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft and code execution
Red Hat Satellite Foreman template preview authorization (TL-2026-2874) is a critical-severity software vulnerability scored CVSS 9.1, first published 2026-10-03. It has no confirmed attribution, affects Red Hat Red Hat Satellite, references 2 CVEs (CVE-2026-96659, CVE-2026-96658), maps to 6 MITRE ATT&CK techniques (T1005, T1059.004, T1078), and is covered by 9 detection rules and 7 indicators of compromise.
Key facts for TL-2026-2874
- Threat ID
- TL-2026-2874
- Severity
- CRITICAL
- CVSS
- 9.1 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-10-03
- Last reviewed
- 2026-10-03
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, government administration, finance, telecoms, health
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 7
Malware and tooling in Red Hat Satellite Foreman template preview authorization
Malware and tooling: Foreman Safemode
An authorization weakness (CWE-267) in Foreman template preview endpoints, used by Red Hat Satellite 6.16, 6.18 and 6.19, lets a low-privileged Viewer-role user with network access read admin-only data such as host root passwords, and potentially execute code as the foreman service account when Safemode protections are disabled. A related Safemode sandbox bypass leading to RCE is tracked as CVE-2026-96658 (CVSS 9.9). Patches were released and the flaw disclosed on 2026-10-01; no active exploitation or public PoC is reported.
How Red Hat Satellite Foreman template preview authorization works
CVE-2026-96659 is a flaw in Foreman, the provisioning and lifecycle component embedded in Red Hat Satellite. Red Hat describes it as excessive permissions granted to Viewer-role users on certain API endpoints, notably the template preview endpoint (/template/preview). An authenticated user holding only the low-privileged Viewer role can submit crafted requests to the template preview functionality and retrieve data that should be admin-only, including host root passwords. The weakness is classified as CWE-267 (Privilege Defined With Unsafe Actions; NVD labels it Improper Privilege Management). Red Hat scores it CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L = 9.1 (Red Hat product security rating: Important; NVD: Critical). Exploitation needs network access to the Satellite web/API interface and a valid Viewer account; no user interaction is required.
If Safemode protections for Foreman templates are disabled or bypassed, the same exposure can escalate to arbitrary command execution as the foreman system account. The Safemode bypass is tracked separately as CVE-2026-96658: an authenticated low-privileged attacker can achieve remote code execution by bypassing the safemode sandbox in the Foreman templating engine through improper handling of delegated methods (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H = 9.9, Red Hat Bugzilla 2534185). The Foreman templating sandbox has a history of such bypasses (for example CVE-2023-0118, an admin-user safe-mode bypass to OS code execution), so the two CVEs should be treated as a chained risk: credential disclosure plus a code-execution path on the provisioning server.
Impact is high because Satellite manages patching, provisioning and configuration for large RHEL fleets; exposed root passwords of managed hosts and code execution as the foreman account on the Satellite server can support lateral movement across the managed estate. Red Hat reported the issue on 2026-09-17 and shipped fixes on 2026-10-01. Fixed Foreman 3.12.0.23-1 is delivered via Satellite 6.16.14 (RHSA-2026:74506, RHEL 8 and 9); Satellite 6.18 is covered by RHSA-2026:74504 and 6.19 by RHSA-2026:74503 (RHEL 9). Red Hat's Bugzilla entry also lists Satellite 6.17 with RHSA-2026:74505, and NVD references all four advisories. The sources do not report in-the-wild exploitation, a public proof of concept, CISA KEV listing, attribution, or network IOCs. Recommended mitigations: apply the errata immediately, remove unnecessary Viewer-role accounts, verify Safemode remains enabled, and monitor template preview requests for abuse.
MITRE ATT&CK techniques used in TL-2026-2874
Collection
Execution
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Credential Access
T1212 Exploitation for Credential Access; T1552 Unsecured Credentials
Affected products and versions in Red Hat Satellite Foreman template preview authorization
- Red Hat — Red Hat Satellite
Vulnerable versions: 6.16 (RHEL 8, RHEL 9); 6.17 (RHEL 9, per Red Hat Bugzilla); 6.18 (RHEL 9); 6.19 (RHEL 9)
Fixed in: 6.16.14 (Foreman 3.12.0.23-1); RHSA-2026:74504 (6.18); RHSA-2026:74503 (6.19); RHSA-2026:74505 (6.17) - Foreman Project — Foreman
Vulnerable versions: Foreman builds shipped before 3.12.0.23 in Satellite 6.16
Fixed in: 3.12.0.23-1
Remediation for Red Hat Satellite Foreman template preview authorization
Patches
- Foreman 3.12.0.23-1 via Satellite 6.16.14 (RHEL 8 and RHEL 9)
- Satellite 6.18 on RHEL 9: RHSA-2026:74504
- Satellite 6.19 on RHEL 9: RHSA-2026:74503
Immediate actions
- Apply Red Hat Satellite security errata RHSA-2026:74506 (6.16.14), RHSA-2026:74504 (6.18) and RHSA-2026:74503 (6.19) / RHSA-2026:74505 (6.17)
- Review and remove unnecessary Viewer-role account access on Satellite
- Verify Foreman Safemode protection remains enabled
- Rotate host root passwords that may have been exposed through template preview
Workarounds
- No dedicated workaround published; Red Hat advises upgrading to a fixed version or contacting Red Hat support
Longer-term hardening
- Restrict network access to the Satellite web UI and API to management networks
- Monitor and alert on template preview requests by low-privileged users
- Apply least-privilege role design for Foreman/Satellite users
CVEs associated with Red Hat Satellite Foreman template preview authorization
CVE-2026-96659, CVE-2026-96658
Weaknesses (CWE) in Red Hat Satellite Foreman template preview authorization
CWE-267
Timeline of Red Hat Satellite Foreman template preview authorization
- Earlier Foreman template safe-mode bypass CVE-2023-0118 (admin-level arbitrary code execution through templates) establishes the sandbox as a recurring weak point
- Excessive Viewer-role permissions on Foreman template preview endpoints reported to Red Hat (Bugzilla 2536844)
- CVE-2026-96659 (CVSS 9.1) and related Safemode bypass CVE-2026-96658 (CVSS 9.9) publicly disclosed and published to NVD
- Red Hat releases Satellite errata RHSA-2026:74503, 74504, 74505 and 74506, including Satellite 6.16.14 with Foreman 3.12.0.23-1
- Cyber Security News reports the flaw enabling root password theft and code execution on Red Hat Satellite
- No in-the-wild exploitation, public PoC or CISA KEV listing reported in the reviewed sources
Sources cited for Red Hat Satellite Foreman template preview authorization
- Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks
- Red Hat CVE-2026-96659
- Red Hat CVE-2026-96658
- NVD CVE-2026-96659
- Red Hat Bugzilla 2536844 (CVE-2026-96659)
- Red Hat Bugzilla 2534185 (CVE-2026-96658)
- RHSA-2026:74506 Satellite 6.16.14 Async Update
- RHSA-2026:74504 Satellite 6.18
- RHSA-2026:74503 Satellite 6.19
- CVE-2023-0118: Foreman arbitrary code execution through templates (precedent)
More in vulnerability
- Critical Capacitor WebView Navigation Guard Bypass Lets Malicious Links Access App Data and Native Features (CVE-2026-103922)
- Apple iCloud Mail Parser Flaws Let Free Accounts Spoof Any @icloud.com Sender and Pass SPF/DKIM/DMARC
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to unauthenticated admin access and RCE (CVE-2026-61500) under active exploitation
- Microsoft Reissues September 2026 Exchange Server Updates (V2) for CVE-2026-96940 Mailbox Authorization Flaw
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898, CVE-2026-12627)
Detection coverage for TL-2026-2874
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2874 across Splunk SPL, Microsoft KQL and Sigma, covering 7 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.