A flaw was found in rubygem-foreman_remote_execution. (CVE-2026-12405)
A command injection vulnerability (CVE-2026-12405) exists in the Red Hat Satellite API (/api/v2/job_invocations) related to the rubygem-foreman_remote_execution component. When a job template has the effective_user property marked as overridable, the API fails to properly sanitize this input, allowing an attacker with job execution permissions to inject arbitrary shell commands executed with the privileges of the execution user. Red Hat has released an official security update addressing this issue in Red Hat Satellite 6.19 for RHEL 9.
AI Analysis
Technical Summary
CVE-2026-12405 is a command injection vulnerability in rubygem-foreman_remote_execution used by Red Hat Satellite. The flaw occurs when the effective_user parameter in job templates marked as overridable is not properly sanitized during API requests to /api/v2/job_invocations. This allows an attacker with permissions to execute job templates to inject arbitrary shell commands, which are executed on the target infrastructure with the privileges of the execution user. The vulnerability does not depend on the job template content itself but on the instantiation process of the job execution environment by the Satellite server. Red Hat has issued a security advisory (RHSA-2026:74503) providing an official fix for Red Hat Satellite 6.19 on RHEL 9.
Potential Impact
An attacker with permissions to execute job templates on Red Hat Satellite can exploit this vulnerability to execute arbitrary shell commands on target infrastructure with the privileges of the execution user. This can lead to full compromise of the affected systems, including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 8.8 (High), reflecting network attack vector, low attack complexity, required privileges, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released an official security update fixing this vulnerability in Red Hat Satellite 6.19 for RHEL 9. Users should apply the update provided in RHSA-2026:74503 as soon as possible. The vendor advisory is the authoritative source for remediation guidance. No additional mitigations are specified beyond applying the official patch.
A flaw was found in rubygem-foreman_remote_execution. (CVE-2026-12405)
Description
A command injection vulnerability (CVE-2026-12405) exists in the Red Hat Satellite API (/api/v2/job_invocations) related to the rubygem-foreman_remote_execution component. When a job template has the effective_user property marked as overridable, the API fails to properly sanitize this input, allowing an attacker with job execution permissions to inject arbitrary shell commands executed with the privileges of the execution user. Red Hat has released an official security update addressing this issue in Red Hat Satellite 6.19 for RHEL 9.
CVSS v3.1
Score 8.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-12405 is a command injection vulnerability in rubygem-foreman_remote_execution used by Red Hat Satellite. The flaw occurs when the effective_user parameter in job templates marked as overridable is not properly sanitized during API requests to /api/v2/job_invocations. This allows an attacker with permissions to execute job templates to inject arbitrary shell commands, which are executed on the target infrastructure with the privileges of the execution user. The vulnerability does not depend on the job template content itself but on the instantiation process of the job execution environment by the Satellite server. Red Hat has issued a security advisory (RHSA-2026:74503) providing an official fix for Red Hat Satellite 6.19 on RHEL 9.
Potential Impact
An attacker with permissions to execute job templates on Red Hat Satellite can exploit this vulnerability to execute arbitrary shell commands on target infrastructure with the privileges of the execution user. This can lead to full compromise of the affected systems, including confidentiality, integrity, and availability impacts. The CVSS v3.1 base score is 8.8 (High), reflecting network attack vector, low attack complexity, required privileges, no user interaction, and high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
Red Hat has released an official security update fixing this vulnerability in Red Hat Satellite 6.19 for RHEL 9. Users should apply the update provided in RHSA-2026:74503 as soon as possible. The vendor advisory is the authoritative source for remediation guidance. No additional mitigations are specified beyond applying the official patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-9jhx-3c73-g9rh
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-12405"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6abeb3e7a43b0b3b89ed1e83
Added to database: 10/01/2026, 19:26:31 UTC
Last enriched: 10/01/2026, 19:30:27 UTC
Last updated: 10/02/2026, 02:45:55 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.