Database/Control plane, storage & DevOps
Foreman / Red Hat Satellite: shell injection via foreman-rake db:dump and db:import_dump paths
Impact
Foreman and its Red Hat Satellite build are what many fleets use to provision, patch and inventory bare-metal GPU nodes, so the Satellite host holds provisioning templates, subscription credentials and root-equivalent reach into every node it manages. The backup and restore rake tasks pass the destination path (db:dump) and the file path (db:import_dump) into a Ruby system() call without sanitising them, so an operator who is only supposed to be able to run backups can append shell commands and have them run as whatever account the sudo rule grants - typically root. CVSS marks the scope as changed and confidentiality, integrity and availability all high, which matches: a backup operator becomes full owner of the management host. Nothing on a GPU node has to be touched for the attacker to then push changed content or kickstart configuration to the fleet.
Who can reach it
Local and authenticated: a user who already holds permission to run foreman-rake, most commonly through a restricted sudoers entry intended to allow only backups and restores. No network path and no interaction from another user is needed.
What to do
Apply the Red Hat errata for your Satellite release (RHSA-2026:74503 / 74504 / 74506 cover Satellite 6.16 on RHEL 8 and 9 and 6.18 / 6.19 on RHEL 9) and restart the Foreman services; the Satellite host itself is a management node, so this is a service window on the control plane rather than a fleet-wide reboot. Until patched, remove or tighten any sudoers rule that lets a non-root account invoke foreman-rake with caller-supplied paths - the rule is the thing that turns this into privilege escalation. No GPU node needs to be drained.
References
Related entries
- IBM AIX and PowerVM VIOS: improper authentication allows remote access to NFS exportsCVE-2026-16686 · IBM AIX / PowerVM VIOS NFS server (export authentication)High
- Cisco Intersight Device Connector for Nutanix Prism Central: The device connector exposes an unauthenticated APICVE-2026-5944 · Cisco Intersight Device Connector for Nutanix Prism CentralHigh
- OpenChoreo Backstage backend: hardcoded auth bypass exposes /api/* to unauthenticated callersCVE-2026-73666 · OpenChoreo Backstage backend (default auth policy)High
- HPE OneView: remotely exploitable session hijacking against the infrastructure management consoleCVE-2026-76718 · HPE OneView (web interface, session handling)High
- GitLab CE/EE: unsanitized Markdown JSON table content induces state-changing requests as a targeted userCVE-2026-78252 · GitLab CE/EE (Markdown JSON table renderer)High
- Ceph RGW (SigV4 signature verifier): Anyone handed a single presigned PUT URL gets more authority than whoever signedNCVD-2026-039-ceph-rgw-sigv4-signature-verifie · Ceph RGW (SigV4 signature verifier)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.