Vulnerability Details CVE-2026-12541
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 69.7%
CVSS Severity
CVSS v3 Score 8.2
Products affected by CVE-2026-12541
-
cpe:2.3:a:redhat:satellite:*
-
cpe:2.3:a:redhat:satellite:6.0
-
cpe:2.3:a:redhat:satellite:6.16
-
cpe:2.3:a:redhat:satellite:6.16.0.1
-
cpe:2.3:a:redhat:satellite:6.16.1
-
cpe:2.3:a:redhat:satellite:6.16.2
-
cpe:2.3:a:redhat:satellite:6.16.3
-
cpe:2.3:a:redhat:satellite:6.17
-
cpe:2.3:a:redhat:satellite:6.17.1
-
cpe:2.3:a:redhat:satellite:6.17.2
-
cpe:2.3:a:redhat:satellite:6.17.3
-
cpe:2.3:a:redhat:satellite:6.17.4
-
cpe:2.3:a:redhat:satellite:6.17.5
-
cpe:2.3:a:redhat:satellite:6.17.6
-
cpe:2.3:a:redhat:satellite:6.17.6.1
-
cpe:2.3:a:redhat:satellite:6.17.6.2
-
cpe:2.3:a:redhat:satellite:6.17.6.3
-
cpe:2.3:a:redhat:satellite:6.17.7
-
cpe:2.3:a:redhat:satellite:6.17.8
-
cpe:2.3:a:redhat:satellite:6.17.9
-
cpe:2.3:a:theforeman:foreman:-
-
cpe:2.3:o:redhat:enterprise_linux:8.0