A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2026:34365 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:34366 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:34367 | Vendor Advisory |
| https://access.redhat.com/errata/RHSA-2026:34368 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2026-5136 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2452970 | Issue Tracking Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
Configuration 4 (hide)
| AND |
|
Configuration 5 (hide)
|
History
09 Jul 2026, 02:39
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Redhat enterprise Linux
Redhat satellite Theforeman Redhat Theforeman foreman |
|
| CPE | cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:* cpe:2.3:a:theforeman:foreman:*:*:*:*:*:*:*:* cpe:2.3:a:redhat:satellite:*:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* |
|
| References | () https://access.redhat.com/errata/RHSA-2026:34365 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:34366 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:34367 - Vendor Advisory | |
| References | () https://access.redhat.com/errata/RHSA-2026:34368 - Vendor Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-5136 - Vendor Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2452970 - Issue Tracking, Vendor Advisory |
02 Jul 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
01 Jul 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-01 14:16
Updated : 2026-07-09 02:39
NVD link : CVE-2026-5136
Mitre link : CVE-2026-5136
CVE.ORG link : CVE-2026-5136
JSON object : View
Products Affected
redhat
- enterprise_linux
- satellite
theforeman
- foreman
CWE
CWE-266
Incorrect Privilege Assignment
