A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. (CVE-2026-12541)
A command injection vulnerability exists in Foreman affecting the foreman-rake db:dump and db:import_dump tasks. The flaw allows an attacker with foreman-rake execution permissions to inject arbitrary OS commands via unsanitized input parameters. This vulnerability has a high severity score and is addressed by a security update from Red Hat.
AI Analysis
Technical Summary
CVE-2026-12541 is an OS command injection vulnerability in Foreman, specifically in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter during backups and the file parameter during imports before passing them to a Ruby system() call. An attacker with permissions to execute foreman-rake (such as via restricted sudo) can append malicious shell commands to these file paths, potentially leading to full system compromise. Red Hat has issued a security advisory (RHSA-2026:74503) providing patches for Red Hat Satellite 6.19 on RHEL 9 to remediate this issue.
Potential Impact
Successful exploitation allows an attacker with foreman-rake execution permissions to execute arbitrary OS commands with elevated privileges, leading to complete system compromise including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 8.2 (High), reflecting high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A security update is available from Red Hat (RHSA-2026:74503) that fixes this vulnerability. Users of Red Hat Satellite 6.19 on RHEL 9 should apply the update promptly. No additional mitigation steps are required beyond applying the official patch. Ensure that only trusted users have permissions to execute foreman-rake tasks.
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. (CVE-2026-12541)
Description
A command injection vulnerability exists in Foreman affecting the foreman-rake db:dump and db:import_dump tasks. The flaw allows an attacker with foreman-rake execution permissions to inject arbitrary OS commands via unsanitized input parameters. This vulnerability has a high severity score and is addressed by a security update from Red Hat.
CVSS v3.1
Score 8.2high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12541 is an OS command injection vulnerability in Foreman, specifically in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter during backups and the file parameter during imports before passing them to a Ruby system() call. An attacker with permissions to execute foreman-rake (such as via restricted sudo) can append malicious shell commands to these file paths, potentially leading to full system compromise. Red Hat has issued a security advisory (RHSA-2026:74503) providing patches for Red Hat Satellite 6.19 on RHEL 9 to remediate this issue.
Potential Impact
Successful exploitation allows an attacker with foreman-rake execution permissions to execute arbitrary OS commands with elevated privileges, leading to complete system compromise including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 8.2 (High), reflecting high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
A security update is available from Red Hat (RHSA-2026:74503) that fixes this vulnerability. Users of Red Hat Satellite 6.19 on RHEL 9 should apply the update promptly. No additional mitigation steps are required beyond applying the official patch. Ensure that only trusted users have permissions to execute foreman-rake tasks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rcq3-9wpf-p347
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-12541"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6abeb3e3a43b0b3b89ed024b
Added to database: 10/01/2026, 19:26:27 UTC
Last enriched: 10/01/2026, 19:29:20 UTC
Last updated: 10/02/2026, 04:02:07 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.