Redpacketsecurity High-Risk Command Injection Vulnerabilities in Red Hat Satellite
Article Content
- •Two critical command injection vulnerabilities found in Red Hat Satellite's Foreman.
- •Attackers with sudo access can execute arbitrary code through flawed tasks.
- •Immediate patching is required as no practical workarounds exist.
Two command injection vulnerabilities (CVE-2026-12540 and CVE-2026-12541) were discovered in Red Hat Satellite's Foreman component, affecting the foreman-rake tasks. These flaws allow attackers with sudo permissions to execute arbitrary code by injecting shell metacharacters into system commands. The vulnerabilities impact organizations using Red Hat Satellite for infrastructure management, particularly those with broad delegated access. Red Hat has classified both vulnerabilities as high-risk with a CVSS score of 8.2. No known exploitation has been reported in the wild, but immediate remediation is advised. Affected tasks include errors:fetch_log and db:dump/db:import_dump, which are crucial for log management and database operations. Patching is required as no practical workarounds are available. Administrators are urged to review sudo permissions and audit logs for suspicious activity.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track Red Hat and CVE-2026-12540 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What systems are affected?
Is there any known exploitation?
What should I do to mitigate this risk?
Continue Reading
Parallels Desktop Vulnerability Allows Local Users to Gain Root Access A critical vulnerability in Parallels Desktop, identified as CVE-2026-90894 and dubbed 'ParaShells', allows any local user on a Mac to execute code with root privileges. The flaw arises from a world-writable Unix socket and weak local-client authentication in the prl_disp_service, which runs as root. This…
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…