CVE-2026-107151: Missing Authentication for Critical Function in Red Hat Red Hat Satellite 6
Description
CVE-2026-107151 is a vulnerability in Red Hat Satellite 6 involving missing authentication for critical remote-execution task updates in the smart_proxy_dynflow package. An attacker who knows the identifier of a running job can send forged job output reports without a one-time token, marking jobs as success or failure. This affects configurations where remote execution is set to pull or pull-mqtt mode. The vulnerability has a medium severity with a CVSS score of 5.9.
CVSS v3.1
Score 5.9medium
Affected software
Red Hat
Red Hat Satellite 6
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from missing authentication checks in the progress and completion callbacks of remote-execution task updates within the smart_proxy_dynflow package of Red Hat Satellite 6. Specifically, these callbacks accept reports even when the one-time token is missing. An attacker or user who knows the identifier of a running job can send arbitrary job output, thereby marking the job as successful or failed. This issue applies when remote execution is configured in pull or pull-mqtt mode. The vulnerability does not affect confidentiality or availability but impacts integrity by allowing unauthorized modification of job results.
Potential Impact
The vulnerability allows an unauthenticated network attacker or user who knows a running job's identifier to forge job output reports and alter the recorded status of that job to success or failure. This compromises the integrity of job execution results but does not affect confidentiality or availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
The vendor advisory from Red Hat should be consulted for current remediation guidance. No explicit patch or fix information is provided in the input data. Patch status is not yet confirmed — check the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-107151 for updates. Until a fix is applied, consider restricting network access to the remote execution service and monitoring for anomalous job status changes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-10-07T10:19:09.047Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-107151","vendor":"Red Hat"}]
Threat ID: 6ac643412cdf04f6564d0ab9
Added to database: 10/07/2026, 13:04:01 UTC
Last enriched: 10/07/2026, 13:18:38 UTC
Last updated: 10/07/2026, 18:56:12 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.