Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication has been found in remote-execution task updates in the smart_proxy_dynflow package. The progress and completion callbacks accept a report when the one-time token is missing. A network attacker or user must already know the identifier of a running job. This applies when remote execution is set to pull or pull-mqtt mode. They can send their own job output and mark the job as a success or a failure. The job is then recorded with that result. | |
| Title | Rubygem-smart_proxy_dynflow: task update and done callbacks accept unauthenticated requests | |
| First Time appeared |
Redhat
Redhat satellite |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:/a:redhat:satellite:6 | |
| Vendors & Products |
Redhat
Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-07T12:36:29.932Z
Reserved: 2026-10-07T10:19:09.047Z
Link: CVE-2026-107151
No data.
Status : Awaiting Analysis
Published: 2026-10-07T13:17:19.783
Modified: 2026-10-07T14:47:21.140
Link: CVE-2026-107151
No data.
OpenCVE Enrichment
No data.