Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 27 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Red Hat
Red Hat red Hat Satellite 6 |
|
| Vendors & Products |
Red Hat
Red Hat red Hat Satellite 6 |
Thu, 27 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving an audited template revision. An authenticated, low privileged user with a template-related permission, such as view_ptables, can obtain historical template contents belonging to another organization or location by supplying the corresponding audit ID. This can result in unauthorized disclosure of historical template contents, which may contain sensitive configuration information, credentials, or other secrets. The REST API revision endpoints correctly restrict this lookup. | |
| Title | Foreman: cross-tenant disclosure of template revisions via unauthorized audit lookup | |
| First Time appeared |
Redhat
Redhat satellite |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:satellite:6 | |
| Vendors & Products |
Redhat
Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-27T10:55:31.059Z
Reserved: 2026-08-27T09:57:41.073Z
Link: CVE-2026-81658
Updated: 2026-08-27T14:47:46.047Z
Status : Received
Published: 2026-08-27T13:18:42.037
Modified: 2026-08-27T13:18:42.037
Link: CVE-2026-81658
No data.
OpenCVE Enrichment
Updated: 2026-08-27T14:45:17Z