Red Hat released Important security updates for Red Hat Satellite that address six vulnerabilities in Satellite 6.17 and 6.18 deployments on RHEL 9. The advisories cover Red Hat Satellite 6.17.9.1 and Red Hat Satellite 6.18.7.1, along with affected Satellite Capsule packages, and remediate flaws in pulpcore and yggdrasil-worker-forwarder components used by the platform.
The fixed issues include an authorization bypass in gRPC-Go, multiple Go-related denial-of-service vulnerabilities, an IDNA/Punycode privilege-escalation issue, and a pulpcore directory traversal validator bypass. Red Hat said the updates affect Satellite 6.17 and 6.18 environments for x86_64 on RHEL 9, and one advisory also resolves an upgrade bug that could cause failures during migration from Satellite 6.16 to 6.17 with a pulpcore-manager rpm-datarepair CommandError.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-04, Red Hat's Bugzilla tracked CVE-2026-12515, a Katello authorization flaw in ContentUploadsController that let a user with limited edit_products permissions query the /katello/api/v2/repositories/:id/content_uploads endpoint for repositories outside their authorized product scope, causing information disclosure. Red Hat said the issue was addressed in Satellite 6.16, 6.17, and 6.18 via RHSA-2026:50223, RHSA-2026:50222, and RHSA-2026:50263.
On 2026-08-04, Red Hat published RHSA-2026:50223, an Important security advisory for Red Hat Satellite 6.16 on RHEL 8 and RHEL 9. The update released Red Hat Satellite 6.16.12 Async Update and fixed multiple vulnerabilities in PyJWT, puppetserver/Jetty, Pillow, Faraday, Katello, Nokogiri, libsolv, and puppet-agent/OpenSSL, along with two bug fixes.
On 2026-08-04, Red Hat published RHSA-2026:50222, an Important security advisory for Red Hat Satellite 6.17 on RHEL 9. The update released Red Hat Satellite 6.17.10 and fixed multiple vulnerabilities in PyJWT, puppetserver/Jetty, Katello, OpenSSL, Pillow, Faraday, and Nokogiri, along with several Satellite bug fixes and a switch to OpenVox.
On 2026-08-04, Red Hat published RHSA-2026:50263, an Important async security advisory for Red Hat Satellite 6.18 on RHEL 9. The update released Red Hat Satellite 6.18.8 and fixed multiple vulnerabilities in puppetserver/Jetty, PyJWT, Katello, Faraday, Pillow, Nokogiri, and puppet-agent/OpenSSL, along with several non-security bug fixes.
On 2026-07-20, Red Hat published RHSA-2026:42151, an Important security advisory for Red Hat Satellite 6.18 for RHEL 9. The update released Red Hat Satellite 6.18.7.1 and fixed six vulnerabilities affecting yggdrasil-worker-forwarder and pulpcore.
On 2026-07-20, Red Hat published RHSA-2026:42150, an Important security advisory for Red Hat Satellite 6.17 for RHEL 9. The update released Red Hat Satellite 6.17.9.1 Async Update and fixed six vulnerabilities in pulpcore and yggdrasil-worker-forwarder, while also resolving upgrade bug SAT-47477.
On 2026-07-01, Red Hat's Bugzilla tracked CVE-2026-5136, a Foreman privilege escalation flaw in the Usergroup model that let an authenticated user with create_usergroups or edit_usergroups permissions assign arbitrary roles, including administrative roles, and add themselves to gain administrator-level access. Red Hat said the issue was addressed in Satellite 6.16, 6.17, and 6.18 via RHSA-2026:34367, RHSA-2026:34366, and RHSA-2026:34368.
On 2026-07-01, Red Hat's Bugzilla tracked CVE-2026-5142, a Foreman taxonomy scoping bypass in KeyPairsController#show that could let an authenticated user with view_keypairs permission download private SSH keys from other organizations. Red Hat said the issue affected multi-tenant Satellite deployments and was addressed in Satellite 6.16, 6.17, and 6.18 via RHSA-2026:34367, RHSA-2026:34366, and RHSA-2026:34368.
On 2026-07-01, Red Hat's Bugzilla tracked CVE-2026-5138, a Foreman cross-tenant information disclosure flaw caused by improper validation of nested taxonomy parameters. The issue could let an authenticated user with host creation or editing privileges access infrastructure metadata from unauthorized organizations or locations, and Red Hat said it was addressed in Satellite 6.16, 6.17, and 6.18 via RHSA-2026:34367, RHSA-2026:34366, and RHSA-2026:34368.
On 2026-07-01, Red Hat's Bugzilla tracked CVE-2026-5135, a broken access control flaw in Foreman that could let an authenticated user with host-edit permissions retarget lookup value overrides to other hosts and alter managed host configurations across organization and location boundaries. The record stated the issue was addressed in Red Hat Satellite 6.16, 6.17, and 6.18 via RHSA-2026:34367, RHSA-2026:34366, and RHSA-2026:34368.
On 2026-07-01, Red Hat published RHSA-2026:34368, an Important security advisory for Red Hat Satellite 6.18 on RHEL 9. The update released Red Hat Satellite 6.18.7 Async Update and fixed multiple vulnerabilities in Foreman, yggdrasil-worker-forwarder, and python-pillow, along with bug fix SAT-47204.
On 2026-07-01, Red Hat published RHSA-2026:34366, an Important security advisory for Red Hat Satellite 6.17 on RHEL 9. The update released Red Hat Satellite 6.17.9 and fixed multiple vulnerabilities in Foreman, python-pillow, dynflow-utils, and yggdrasil-worker-forwarder, along with two non-security bug fixes.
On 2026-06-18, Red Hat published RHSA-2026:27076, an Important security advisory for Red Hat Satellite 6.16 on RHEL 8 and RHEL 9. The update released Red Hat Satellite 6.16.9 Async Update, fixing multiple vulnerabilities in yggdrasil-worker-forwarder, dynflow-utils, python-pillow, and Go components, along with two Capsule-related bug fixes.
On 2026-06-15, Red Hat's Bugzilla tracked CVE-2026-48526, a PyJWT authentication bypass flaw affecting versions prior to 2.13.0 when verifiers accepted both asymmetric and HMAC algorithms. The record said improper validation of JSON Web Keys could let an attacker use the issuer's public key as an HMAC secret, and noted later fixes across products including Satellite 6.16, 6.17, and 6.18.
On 2026-03-06, Red Hat's Bugzilla received Bug 2445356 tracking CVE-2026-25679, a high-severity flaw in Go's net/url package involving incorrect parsing of IPv6 host literals and insufficient host/authority validation in url.Parse. The record linked the issue to broad downstream impact across Red Hat products, including Satellite 6.16, 6.17, and 6.18.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
17 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.