A flaw was found in rubygem-katello. (CVE-2026-56098)
A vulnerability in rubygem-katello's RegistryProxiesController allows an authorization bypass due to a missing return statement in the registry_authorize filter. This flaw enables unauthorized requests to continue executing subsequent business logic, leading to information disclosure by enumerating valid Users, Organizations, and Products. The issue has a medium severity with a CVSS score of 4.3. Red Hat has released a security advisory with an official fix for Red Hat Satellite 6.19 on RHEL 9.
AI Analysis
Technical Summary
CVE-2026-56098 describes an authorization bypass vulnerability in the RegistryProxiesController of rubygem-katello. The flaw arises because the unauthorized method triggers an error response but does not halt further execution due to a missing return statement in the registry_authorize filter. This allows the application to proceed with business logic and database validation filters, enabling an attacker with limited privileges to enumerate internal resources such as Users, Organizations, and Products across the instance. The vulnerability is tracked with a CVSS 3.1 base score of 4.3 (medium severity). Red Hat's advisory (RHSA-2026:74503) confirms an official fix is available for Red Hat Satellite 6.19 on RHEL 9.
Potential Impact
The vulnerability allows an attacker with limited privileges to bypass authorization controls and enumerate sensitive internal resources, including Users, Organizations, and Products. This information disclosure could aid further targeted attacks or reconnaissance but does not directly lead to integrity or availability impacts. The CVSS score reflects a low complexity attack vector with network access and no user interaction required.
Mitigation Recommendations
An official fix is available from Red Hat as detailed in advisory RHSA-2026:74503. Users of Red Hat Satellite 6.19 on RHEL 9 should apply the update to remediate this vulnerability. No additional mitigation steps are required beyond applying the vendor-provided patch.
A flaw was found in rubygem-katello. (CVE-2026-56098)
Description
A vulnerability in rubygem-katello's RegistryProxiesController allows an authorization bypass due to a missing return statement in the registry_authorize filter. This flaw enables unauthorized requests to continue executing subsequent business logic, leading to information disclosure by enumerating valid Users, Organizations, and Products. The issue has a medium severity with a CVSS score of 4.3. Red Hat has released a security advisory with an official fix for Red Hat Satellite 6.19 on RHEL 9.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-56098 describes an authorization bypass vulnerability in the RegistryProxiesController of rubygem-katello. The flaw arises because the unauthorized method triggers an error response but does not halt further execution due to a missing return statement in the registry_authorize filter. This allows the application to proceed with business logic and database validation filters, enabling an attacker with limited privileges to enumerate internal resources such as Users, Organizations, and Products across the instance. The vulnerability is tracked with a CVSS 3.1 base score of 4.3 (medium severity). Red Hat's advisory (RHSA-2026:74503) confirms an official fix is available for Red Hat Satellite 6.19 on RHEL 9.
Potential Impact
The vulnerability allows an attacker with limited privileges to bypass authorization controls and enumerate sensitive internal resources, including Users, Organizations, and Products. This information disclosure could aid further targeted attacks or reconnaissance but does not directly lead to integrity or availability impacts. The CVSS score reflects a low complexity attack vector with network access and no user interaction required.
Mitigation Recommendations
An official fix is available from Red Hat as detailed in advisory RHSA-2026:74503. Users of Red Hat Satellite 6.19 on RHEL 9 should apply the update to remediate this vulnerability. No additional mitigation steps are required beyond applying the vendor-provided patch.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-f6cg-x72x-c392
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-56098"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Patch Information
Threat ID: 6abeb3e1a43b0b3b89ecc914
Added to database: 10/01/2026, 19:26:25 UTC
Last enriched: 10/01/2026, 19:27:01 UTC
Last updated: 10/02/2026, 02:45:56 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.