Skip to content
High-Risk Command Injection Vulnerabilities in Red Hat Satellite

High-Risk Command Injection Vulnerabilities in Red Hat Satellite

First seen 2 Oct 2026, 01:04 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 2, 2026 at 02:07 UTC
  • •Two critical command injection vulnerabilities found in Red Hat Satellite's Foreman.
  • •Attackers with sudo access can execute arbitrary code through flawed tasks.
  • •Immediate patching is required as no practical workarounds exist.

Two command injection vulnerabilities (CVE-2026-12540 and CVE-2026-12541) were discovered in Red Hat Satellite's Foreman component, affecting the foreman-rake tasks. These flaws allow attackers with sudo permissions to execute arbitrary code by injecting shell metacharacters into system commands. The vulnerabilities impact organizations using Red Hat Satellite for infrastructure management, particularly those with broad delegated access. Red Hat has classified both vulnerabilities as high-risk with a CVSS score of 8.2. No known exploitation has been reported in the wild, but immediate remediation is advised. Affected tasks include errors:fetch_log and db:dump/db:import_dump, which are crucial for log management and database operations. Patching is required as no practical workarounds are available. Administrators are urged to review sudo permissions and audit logs for suspicious activity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
CVE-2026-12540 and CVE-2026-12541 published
Red Hat disclosed two command injection vulnerabilities in Foreman affecting Red Hat Satellite.
Redpacketsecurity
2026-10-01
Patches released
Red Hat released patches for the vulnerabilities, urging immediate application to mitigate risks.
Redpacketsecurity

More articles in this cluster (5)

Following this threat?

Track Red Hat and CVE-2026-12540 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
Red Hat Satellite 6.19 for RHEL 9 is affected by these vulnerabilities.
Is there any known exploitation?
No known exploitation has been reported in the wild for these vulnerabilities.
What should I do to mitigate this risk?
Apply the patches released by Red Hat immediately and review sudo permissions for affected tasks.