Cyber Security News

Critical Red Hat Satellite Flaw Could Enable Root Password Theft and Code Execution Attacks

Red Hat has fixed a high-impact vulnerability in Red Hat Satellite that could allow a low-privileged authenticated user to access sensitive host information, including root passwords.

Under unsafe configurations, the flaw could also escalate to arbitrary command execution as the Foreman service account. Tracked as CVE-2026-96659, the issue affects the Foreman component used by Red Hat Satellite for infrastructure provisioning, configuration management, and lifecycle operations.

Red Hat assigned the vulnerability an Important severity rating and a CVSS v3 score of 9.1. The vulnerability was publicly disclosed on October 1, 2026.

The attacker needs network access and a valid low-privileged account, but does not require user interaction. Successful exploitation can have a high confidentiality impact.

The flaw stems from an authorization weakness in Foreman template preview endpoints. A user assigned only the Viewer role can submit crafted requests to these endpoints and retrieve information that should be available only to higher-privileged administrators.

Red Hat Satellite Vulnerability

According to Red Hat, the affected endpoints can expose sensitive host attributes. This may include host root passwords, creating a serious risk for organizations that use Satellite to provision or manage large fleets of Red Hat Enterprise Linux systems.

The issue is classified under CWE-267, an access-control weakness that can allow users to access restricted features, sensitive data, administrative functions, or identities beyond their assigned permissions.

A compromised Viewer account could therefore become an entry point for broader environment exposure. Stolen root credentials could be used to access managed servers, move laterally across a network, alter workloads, or establish persistence.

The primary impact of CVE-2026-96659 is unauthorized information disclosure. However, Red Hat warned that the security impact becomes more severe when Foreman template Safemode protections have been turned off or can be circumvented.

In such insecure configurations, an attacker may be able to execute arbitrary commands as the Foreman service account. This could give an attacker a foothold on the Satellite server itself, which is particularly concerning because Satellite often holds credentials, host inventory data, provisioning templates, configuration details, and content-management access for enterprise Linux infrastructure.

Red Hat’s Satellite 6.16 advisory also lists CVE-2026-96658, a separate Foreman Safemode bypass flaw that can lead to remote code execution. Organizations should treat these related Foreman security issues as a priority patching event rather than addressing CVE-2026-96659 in isolation.

Red Hat has released fixes for the following products:

ProductPlatformStatusAdvisory
Red Hat Satellite 6.16RHEL 8FixedRHSA-2026:74506
Red Hat Satellite 6.16RHEL 9FixedRHSA-2026:74506
Red Hat Satellite 6.18RHEL 9FixedRHSA-2026:74504
Red Hat Satellite 6.19RHEL 9FixedRHSA-2026:74503

For Satellite 6.16, Red Hat released Foreman version 3.12.0.23-1 for RHEL 8 and RHEL 9 as part of the Satellite 6.16.14 update. The advisory also contains fixes for several other security flaws affecting Foreman and related Satellite components.

Administrators should apply the relevant Red Hat security errata immediately, review all Viewer-role accounts, and remove unnecessary access. They should also verify that Foreman Safemode protection remains enabled and investigate template preview activity for unusual requests or access to sensitive host attributes.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Meta and Microsoft are Actively Cutting Employee Use of Claude AI

Meta and Microsoft are reducing employee use of Anthropic’s Claude AI while pushing their own…

10 minutes ago

ClingSTUN Backdoor Exploits Multiple IoT Vulnerabilities to Gain Persistent Remote Access

ClingSTUN is a Linux backdoor that exploits vulnerable internet-connected devices to give attackers lasting remote…

1 hour ago

FBI Removes Accenture Contractor After Unpatched PeopleSoft Flaw Exposes Thousands of Employees

The FBI removed an Accenture contractor on October 5, 2026, after a missed security patch…

1 hour ago

Google Adds 6 Advanced Protection Features to Android 17 Against Sophisticated Attacks

Google has detailed six Advanced Protection enhancements for Android 17, targeting sophisticated attacks, scams and…

2 hours ago

Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products

Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence,…

2 hours ago

Top 10 Best SAST Tools in 2026 [Ranked & Scored]

The AI-code flood made one truth undeniable: static analysis only matters if developers fix what…

3 hours ago