Threats Tagged 'cve-2026-79654'
View all threats tagged with 'cve-2026-79654'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-79654'
Click on any threat for detailed analysis and mitigation recommendations
0 Red Hat Satellite 6.16.14 and related versions contain multiple critical security vulnerabilities including command injection, unauthenticated information disclosure, server-side template injection, SQL injection, denial of service, cross-site scripting, and authorization bypass. These vulnerabilities affect various components such as rubygem-foreman_remote_execution, foreman, rubygem-hammer_cli, python3.12-dynaconf, yggdrasil-worker-forwarder, nodejs-sanitize-html, python-sqlparse, rubygem-katello, and others. The vulnerabilities allow for potential arbitrary code execution, denial of service, information disclosure, and privilege escalation. Red Hat has released security updates addressing these issues in Red Hat Satellite 6.19.5 for RHEL 9 and other related versions. Join the discussion | GCVE Database | 10/01/2026, 23:06:35 UTC Added: 10/01/2026, 19:26:41 UTC |
0 A flaw was found in rubygem-foreman_remote_execution. A command injection vulnerability exists in the Red Hat Satellite API (/api/v2/job_invocations). When a job template has the effective_user property marked as overridable: true, the application fails to properly sanitize the effective_user input provided during the API request. The exploitation does not rely on the content or logic of the Job Template/playbook itself; rather, the injection occurs during the instantiation of the job execution environment by the Satellite server. An attacker with permissions to execute job templates can inject arbitrary shell commands into this parameter, which are executed on the target infrastructure with the privileges of the execution user. Join the discussion | GCVE Database | 10/01/2026, 23:06:35 UTC Added: 10/01/2026, 19:26:31 UTC |
A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps. Join the discussion | GCVE Database | 08/28/2026, 18:31:23 UTC Added: 10/01/2026, 19:26:39 UTC |
0 CVE-2026-79654 is an authorization bypass vulnerability in Red Hat Satellite 6.16 for RHEL 8 affecting the Katello Content View History API. Authenticated users with permission to view Content Views in one organization may access lifecycle history information of Content Views belonging to other organizations by supplying the identifier of those views. This leads to unauthorized disclosure of publication and promotion events, associated users, and timestamps. The vulnerability has a CVSS score of 4.3, indicating medium severity. Red Hat has published an advisory for this issue and related vulnerabilities in Satellite 6.19, which includes security fixes. No explicit patch version for 6.16 is stated in the input data. The vendor advisory should be consulted for current remediation guidance. Join the discussion | CVE Database V5 | 08/26/2026, 05:37:38 UTC Added: 08/26/2026, 05:52:42 UTC |
Showing 1 to 4 of 4 results