CVE-2026-96659
CVE-2026-96659 is a critical-severity vulnerability with a CVSS 3.x base score of 9.1. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-267.
Key facts
- Severity: Critical (CVSS 3.x base score 9.1)
- EPSS exploit prediction: 0% (23rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-267
- Published:
- Last modified:
Description
A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
Frequently asked questions
- What is CVE-2026-96659?
- A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.
- How severe is CVE-2026-96659?
- CVE-2026-96659 has a CVSS 3.x base score of 9.1, rated critical severity. It is exploitable over network with low attack complexity, requires low privileges and no user interaction. Impact on confidentiality is high, integrity low, and availability low.
- Is CVE-2026-96659 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (23rd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-96659?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-96659 published?
- CVE-2026-96659 was published on 2026-10-01 and last updated on 2026-10-06.
References
- https://access.redhat.com/errata/RHSA-2026:74503
- https://access.redhat.com/errata/RHSA-2026:74504
- https://access.redhat.com/errata/RHSA-2026:74505
- https://access.redhat.com/errata/RHSA-2026:74506
- https://access.redhat.com/security/cve/CVE-2026-96659
- https://bugzilla.redhat.com/show_bug.cgi?id=2536844
Other CWE-267 vulnerabilities
- CVE-2023-22647 — Critical (CVSS 9.9): An Improper Privilege Management vulnerability in SUSE Rancher allowed standard users to leverage their existing…
- CVE-2026-29646 — Critical (CVSS 9.8): In OpenXiangShan NEMU prior to 55295c4, when running with RVH (Hypervisor extension) enabled, a VS-mode guest write to…
- CVE-2021-44547 — Critical (CVSS 9.1): A sandboxing issue in Odoo Community 15.0 and Odoo Enterprise 15.0 allows authenticated administrators to executed…
- CVE-2026-10090 — Critical (CVSS 9.0): A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced…
- CVE-2026-18951 — High (CVSS 8.8): A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly…
- CVE-2026-27314 — High (CVSS 8.8): Privilege escalation in Apache Cassandra 5.0 on an mTLS environment using MutualTlsAuthenticator allows a user with…