GPU VulnDB

Database/Control plane, storage & DevOps

Foreman / Red Hat Satellite: shell injection via foreman-rake db:dump and db:import_dump paths

CVSS 8.2CVE-2026-12541Control plane, storage & DevOpscurated

Impact

Foreman and its Red Hat Satellite build are what many fleets use to provision, patch and inventory bare-metal GPU nodes, so the Satellite host holds provisioning templates, subscription credentials and root-equivalent reach into every node it manages. The backup and restore rake tasks pass the destination path (db:dump) and the file path (db:import_dump) into a Ruby system() call without sanitising them, so an operator who is only supposed to be able to run backups can append shell commands and have them run as whatever account the sudo rule grants - typically root. CVSS marks the scope as changed and confidentiality, integrity and availability all high, which matches: a backup operator becomes full owner of the management host. Nothing on a GPU node has to be touched for the attacker to then push changed content or kickstart configuration to the fleet.

Who can reach it

Local and authenticated: a user who already holds permission to run foreman-rake, most commonly through a restricted sudoers entry intended to allow only backups and restores. No network path and no interaction from another user is needed.

What to do

Apply the Red Hat errata for your Satellite release (RHSA-2026:74503 / 74504 / 74506 cover Satellite 6.16 on RHEL 8 and 9 and 6.18 / 6.19 on RHEL 9) and restart the Foreman services; the Satellite host itself is a management node, so this is a service window on the control plane rather than a fleet-wide reboot. Until patched, remove or tighten any sudoers rule that lets a non-root account invoke foreman-rake with caller-supplied paths - the rule is the thing that turns this into privilege escalation. No GPU node needs to be drained.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.