Red Hat Satellite / Foreman CVE-2026-96659 (CVSS 9.1): Viewer→host root-password disclosure via template preview; RHSA-2026:74503–74506
Red Hat CVE-2026-96659 (published 1 October 2026; Red Hat CVSS 3.1 9.1 Important; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L): authorization weakness (CWE-267) in Foreman template-preview endpoints used by Red Hat Satellite. An authenticated low-privileged user with only the Viewer role can submit crafted requests and retrieve sensitive host attributes that should be admin-only — including host root passwords. If template Safemode protections are disabled or circumvented, Red Hat warns the same flaw class can escalate to arbitrary command execution as the Foreman service account. Affects Satellite/Foreman deployments that expose the vulnerable preview path; companion Critical safemode-bypass CVE-2026-96658 (desk foreman-safemode-96658-20261001) shipped in the same 1 Oct RHSA train. Fixed via RHSA-2026:74503 / 74504 / 74505 / 74506 (Satellite 6.16–6.19 trains per Red Hat CVE page). Wire amplify: Cyber Security News 2 Oct. Primary: Red Hat CVE-2026-96659.
- Product
- Red Hat Satellite (Foreman template preview)
- Versions
- Affected Satellite/Foreman builds prior to RHSA-2026:74503/74504/74505/74506 (Satellite 6.16–6.19 errata per Red Hat). Confirm your train against the live CVE/errata pages.
- CVSS
CVE-2026-96659CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L- Exploited in Australia?
- unknown
- Patch to
- Apply RHSA-2026:74503 / 74504 / 74505 / 74506 (or later errata listing CVE-2026-96659). Until patched: treat Viewer accounts as high risk; restrict template-preview exposure; keep Foreman Safemode enabled (pairs with CVE-2026-96658). Rotate host root/credentials if Viewer-tier users could reach preview endpoints on unpatched Satellite.
Primary: Red Hat — CVE-2026-96659 (Satellite/Foreman template preview authz; 1 Oct 2026) · Vendor: Red Hat Customer Portal — CVE-2026-96659 · CVE: CVE-2026-96659, CVE-2026-96658 · Cyber Security News — Red Hat Satellite Viewer→root-password disclosure (2 Oct 2026)
