Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information, including root passwords.

Under unsafe configurations, the flaw could also escalate to arbitrary command execution as the Foreman service account. Tracked as CVE-2026-96659, the issue affects the Foreman component used by Red Hat Satellite for infrastructure provisioning, configuration management, and lifecycle operations.

Red Hat assigned the vulnerability an Important severity rating and a CVSS v3 score of 9.1. The vulnerability was publicly disclosed on October 1, 2026.

The attacker needs network access and a valid low-privileged account, but does not require user interaction. Successful exploitation can have a high confidentiality impact.

The flaw stems from an authorization weakness in Foreman template preview endpoints. A user assigned only the Viewer role can submit crafted requests to these endpoints and retrieve information that should be available only to higher-privileged administrators.

Red Hat Satellite Vulnerability

According to Red Hat, the affected endpoints can expose sensitive host attributes. This may include host root passwords, creating a serious risk for organizations that use Satellite to provision or manage large fleets of Red Hat Enterprise Linux systems.

The issue is classified under CWE-267, an access-control weakness that can allow users to access restricted features, sensitive data, administrative functions, or identities beyond their assigned permissions.

A compromised Viewer account could therefore become an entry point for broader environment exposure. Stolen root credentials could be used to access managed servers, move laterally across a network, alter workloads, or establish persistence.

The primary impact of CVE-2026-96659 is unauthorized information disclosure. However, Red Hat warned that the security impact becomes more severe when Foreman template Safemode protections have been turned off or can be circumvented.

In such insecure configurations, an attacker may be able to execute arbitrary commands as the Foreman service account. This could give an attacker a foothold on the Satellite server itself, which is particularly concerning because Satellite often holds credentials, host inventory data, provisioning templates, configuration details, and content-management access for enterprise Linux infrastructure.

Red Hat’s Satellite 6.16 advisory also lists CVE-2026-96658, a separate Foreman Safemode bypass flaw that can lead to remote code execution. Organizations should treat these related Foreman security issues as a priority patching event rather than addressing CVE-2026-96659 in isolation.

Red Hat has released fixes for the following products:

Product Platform Status Advisory
Red Hat Satellite 6.16 RHEL 8 Fixed RHSA-2026:74506
Red Hat Satellite 6.16 RHEL 9 Fixed RHSA-2026:74506
Red Hat Satellite 6.18 RHEL 9 Fixed RHSA-2026:74504
Red Hat Satellite 6.19 RHEL 9 Fixed RHSA-2026:74503

For Satellite 6.16, Red Hat released Foreman version 3.12.0.23-1 for RHEL 8 and RHEL 9 as part of the Satellite 6.16.14 update. The advisory also contains fixes for several other security flaws affecting Foreman and related Satellite components.

Administrators should apply the relevant Red Hat security errata immediately, review all Viewer-role accounts, and remove unnecessary access. They should also verify that Foreman Safemode protection remains enabled and investigate template preview activity for unusual requests or access to sensitive host attributes.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks appeared first on Cyber Security News.