GPU VulnDB

Database/Control plane, storage & DevOps

Foreman: command injection in the errors:fetch_log rake task escalates a scoped sudo grant to full code execution

CVSS 8.2CVE-2026-12540Control plane, storage & DevOpscurated

Impact

Foreman and Red Hat Satellite are used to provision, patch and lifecycle-manage bare-metal fleets, including GPU nodes, so the Satellite host holds provisioning templates, subscription credentials and remote-execution authority over every node it manages. The request_id parameter of the errors:fetch_log rake task is interpolated into a shell command (typically grep) without neutralisation, so shell metacharacters break out and run arbitrary commands. Exposure is narrow but the escalation is wide: an operator who hands a support engineer or an automation account a scoped sudoers entry for just this one troubleshooting task has effectively handed over code execution as the target user, and Red Hat scores it as a scope change. There is no remote or unauthenticated path - the attacker must already be local on the Satellite host with sudo rights to that task.

Who can reach it

Local user on the Foreman/Satellite server who has been granted sudo permission to run the foreman-rake errors:fetch_log task. Authentication to the host is required; the Foreman web UI and API are not the attack surface.

What to do

Apply the Red Hat Satellite errata for your release (RHSA-2026:74503 / 74504 / 74506 cover Satellite 6.16 on RHEL 8 and 9 and 6.18/6.19 on RHEL 9) and restart the Satellite services as the errata directs; this is a management-host maintenance window only, no GPU node drain or reboot. Until patched, remove or tighten any sudoers rule that lets a non-root account invoke foreman-rake, since a grant for one rake task is a grant for all of them.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.