CVE-2026-5135

Published Jul 1, 2026

Last updated 14 days ago

Overview

Description
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
Source
secalert@redhat.com
NVD status
Analyzed
Products
satellite, foreman

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Severity
MEDIUM

Weaknesses

secalert@redhat.com
CWE-639

Social media

Hype score
Not currently trending

Configurations