Vulnerability
Published 2026-10-01
Verified 2026-10-02

Foreman / Red Hat Satellite CVE-2026-96658 (CVSS 9.9): safemode sandbox bypass → auth'd RCE; RHSA-2026:74503–74506

Red Hat CNA CVE-2026-96658 (published 1 October 2026; CVSS 3.1 9.9 Critical AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): authenticated low-privilege attacker can achieve remote code execution by bypassing the Foreman templating safemode sandbox — improper handling of delegated methods lets an attacker append unauthorised functions to the allowed execution list and run arbitrary commands on the hosting server. Red Hat Product Security rates Critical because a user with minimal read/view permissions can RCE the underlying Satellite host where Foreman relies on the sandbox to render templates. Fixed packages shipped 1 Oct via RHSA-2026:74506 (Satellite 6.16 el8/el9 rubygem-safemode 0:1.5.0-2), RHSA-2026:74504 (Satellite 6.18 el9 rubygem-safemode), and RHSA-2026:74503 (Satellite Utils 6.19 el9 foreman 0:3.18.0.14-1). Bugzilla 2534185. Primary: Red Hat CVE + RHSAs; Tenable/NVD amplify.

Product
Foreman templating safemode (Red Hat Satellite 6.16 / 6.18 / 6.19)
Versions
Affected: Red Hat Satellite 6.16 (el8/el9), 6.18 (el9), Satellite Utils 6.19 (el9) prior to the RHSA packages below. Fixed packages: rubygem-safemode 0:1.5.0-2.el8sat / 0:1.5.0-2.el9sat (RHSA-2026:74506 / 74504); foreman 0:3.18.0.14-1.el9sat (RHSA-2026:74503).
CVSS
(CVSS 3.1 Critical; Red Hat)
Exploited in Australia?
unknown
Patch to
Apply RHSA-2026:74503 / 74504 / 74506 (or later Satellite errata containing the fixed rubygem-safemode / foreman builds). Restrict template/view privileges on Satellite/Foreman until patched; treat low-privilege Viewer accounts as high risk on unpatched hosts.

Primary: Red Hat — CVE-2026-96658 Foreman safemode bypass RCE (1 Oct 2026) · Vendor: RHSA-2026:74506 — Satellite 6.16 rubygem-safemode fix (also 74504 / 74503) · CVE: CVE-2026-96658 · CVE.org / Red Hat CNA — CVE-2026-96658

vulnerabilities cloud identity