Vulnerability
Published 2026-10-01
Verified 2026-10-03

Red Hat Satellite / Foreman CVE-2026-96659 (CVSS 9.1): Viewer→host root-password disclosure via template preview; RHSA-2026:74503–74506

Red Hat CVE-2026-96659 (published 1 October 2026; Red Hat CVSS 3.1 9.1 Important; CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L): authorization weakness (CWE-267) in Foreman template-preview endpoints used by Red Hat Satellite. An authenticated low-privileged user with only the Viewer role can submit crafted requests and retrieve sensitive host attributes that should be admin-only — including host root passwords. If template Safemode protections are disabled or circumvented, Red Hat warns the same flaw class can escalate to arbitrary command execution as the Foreman service account. Affects Satellite/Foreman deployments that expose the vulnerable preview path; companion Critical safemode-bypass CVE-2026-96658 (desk foreman-safemode-96658-20261001) shipped in the same 1 Oct RHSA train. Fixed via RHSA-2026:74503 / 74504 / 74505 / 74506 (Satellite 6.16–6.19 trains per Red Hat CVE page). Wire amplify: Cyber Security News 2 Oct. Primary: Red Hat CVE-2026-96659.

Product
Red Hat Satellite (Foreman template preview)
Versions
Affected Satellite/Foreman builds prior to RHSA-2026:74503/74504/74505/74506 (Satellite 6.16–6.19 errata per Red Hat). Confirm your train against the live CVE/errata pages.
CVSS
Exploited in Australia?
unknown
Patch to
Apply RHSA-2026:74503 / 74504 / 74505 / 74506 (or later errata listing CVE-2026-96659). Until patched: treat Viewer accounts as high risk; restrict template-preview exposure; keep Foreman Safemode enabled (pairs with CVE-2026-96658). Rotate host root/credentials if Viewer-tier users could reach preview endpoints on unpatched Satellite.

Primary: Red Hat — CVE-2026-96659 (Satellite/Foreman template preview authz; 1 Oct 2026) · Vendor: Red Hat Customer Portal — CVE-2026-96659 · CVE: CVE-2026-96659, CVE-2026-96658 · Cyber Security News — Red Hat Satellite Viewer→root-password disclosure (2 Oct 2026)

vulnerabilities cloud identity linux