Description

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.

INFO

Published Date :

2026-03-26T12:53:09.566Z

Last Modified :

2026-04-08T11:23:19.413Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2026-1961 vulnerability.

Vendors Products
Red Hat
  • Red Hat Satellite 6
Redhat
  • Satellite
  • Satellite Capsule
  • Satellite Maintenance
  • Satellite Utils

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact