A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. This is achieved by modifying the match field through nested host attributes, effectively bypassing authorisation checks. The consequence is the potential for unauthorised modification of managed host configurations across different organisational and location boundaries.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:34365 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:34366 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:34367 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:34368 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-5135 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2452230 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
|
History
09 Jul 2026, 02:39
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
|
| References | () https://access.redhat.com/errata/RHSA-2026:34365 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:34366 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:34367 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:34368 - Vendor Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-5135 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2452230 - Issue Tracking, Vendor Advisory | |
| First Time |
Redhat enterprise Linux
Redhat satellite Theforeman Redhat Theforeman foreman |
02 Jul 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jul 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-01 15:17
Updated : 2026-07-09 02:39
NVD link : CVE-2026-5135
Mitre link : CVE-2026-5135
CVE.ORG link : CVE-2026-5135
JSON object : View
Products Affected
redhat
- enterprise_linux
- satellite
theforeman
- foreman
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
