TL;DR
Red Hat has disclosed a CVSS 9.9 Foreman RCE flaw that lets low-privileged users run commands on Satellite servers. A second Foreman bug leaks host root passwords to Viewer accounts. A third flaw in 389-ds-base can make clients accept failed logins.
- Product: Red Hat (2 products)
- Vulnerabilities: 3 flaws (CVE-2026-96658, CVE-2026-96659, CVE-2026-86345)
- Highest severity: 9.9 (Critical · CVSSv3)
- Worst impact: Foreman: safemode bypass leading to rce
- Status: No confirmed exploitation yet; patches available
- Action: Update to 0:1.5.0-2.el8sat, 0:1.5.0-2.el9sat, 0:3.18.0.14-1.el9sat, 0:3.12.0.23-1.el8sat (+2) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-96658 | 9.9 | CWE-94 | 0:1.5.0-2.el8sat, 0:1.5.0-2.el9sat, 0:3.18.0.14-1.el9sat | Not exploited |
| CVE-2026-96659 | 9.1 | CWE-267 | 0:3.12.0.23-1.el8sat, 0:3.12.0.23-1.el9sat, 0:3.16.0.25-1.el9sat (+1) | Not exploited |
| CVE-2026-86345 | 9 | CWE-923 | — | Not exploited |
See a CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsWhy It Matters
Foreman powers Red Hat Satellite, which manages and patches whole fleets of Linux hosts. So a takeover of the Satellite server can ripple out to every host it controls. Red Hat rates the worst bug Critical. No source has reported exploitation in the wild or a public proof-of-concept so far.
How the Attacks Work
CVE-2026-96658: Safemode Sandbox Escape
Foreman renders templates inside a restricted “safemode” sandbox. However, it mishandles delegated methods. An attacker can add unauthorized functions to the allowed list and run commands on the server. Red Hat warns that “an authenticated user with minimal read permissions can achieve arbitrary remote code execution.”
CVE-2026-96659: Template Preview Data Leak
This bug scores 9.1. A user with only Viewer rights can query template preview endpoints. In turn, they can pull sensitive data such as host root passwords. If safemode is off, this Foreman RCE path also opens up. Red Hat explains the issue in its CVE-2026-96659 advisory.
CVE-2026-86345: StartTLS Injection in 389-ds-base
The LDAP server keeps plaintext bytes buffered during a StartTLS upgrade. An on-path attacker can slip in a crafted message. As a result, a client such as a PAM module may treat a failed login as successful. Despite its 9.0 score, Red Hat rates this one Moderate, since it needs a man-in-the-middle position.
Affected Versions
Red Hat Satellite deployments that use Foreman are exposed to the first two flaws. Systems running 389-ds-base with StartTLS on port 389 face the third. Red Hat lists exact package versions on each CVE page.
Patch and Mitigation Steps
- Apply Red Hat’s Satellite and 389-ds-base updates as they ship.
- Keep template safemode enabled in Foreman.
- Review who holds Viewer roles and trim them.
- For LDAP, disable StartTLS on port 389 and require ldaps on port 636, as the CVE-2026-86345 page advises.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!