Red Hat released security updates for Satellite and Capsule deployments addressing vulnerabilities that could expose provisioning secrets or enable code execution across managed infrastructure. Advisories RHSA-2026:74504, RHSA-2026:74505, and RHSA-2026:74506 deliver Satellite 6.18.10, 6.17.12, and 6.16.14, respectively, fixing 23–24 CVEs per release. Key flaws include CVE-2026-12423, which lets unauthenticated attackers retrieve provisioning templates containing root password hashes, internal network details, and build tokens while hosts are being provisioned; CVE-2026-12405, which permits command injection by users with job-template execution permissions when the effective-user parameter is overridable; and CVE-2026-12540, which enables command injection through a log-fetch task available to users with specific sudo permissions. Separately, CVE-2026-96659, rated CVSS 9.1, allows low-privileged authenticated users to access sensitive host information through Foreman template previews, with potential code execution when Safemode protections are disabled or bypassed. Fixes for that flaw are available for Satellite 6.16, 6.18, and 6.19.
The updates also address a Foreman Safemode bypass, Dynaconf server-side template injection, and vulnerabilities across Katello, GitPython, Go components, and other dependencies. The three release advisories carry Critical headers, although their descriptive text rates the security impact Important; none reports active exploitation. Administrators should apply prerequisite errata and the appropriate security updates to affected Satellite Server and Capsule Server installations, review Viewer-role and job-execution permissions, keep Safemode enabled, and investigate suspicious template-preview activity. Satellite 6.16.14 introduces an operational change: unattended template downloads for Red Hat-family operating systems require valid provisioning tokens, disrupting Generic and Subnet Bootdisk workflows. Full Host Bootdisks support the tokens; disabling enforcement restores the alternative workflows but reopens unauthenticated access to potentially sensitive provisioning data.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2026:74506 for Satellite and Capsule 6.16 on RHEL 8 and RHEL 9, addressing 23 CVEs. The update requires valid tokens for unattended template downloads associated with Redhat-family operating systems, disrupting Generic and Subnet Bootdisk workflows; Full Host Bootdisks remain supported.
Red Hat issued RHSA-2026:74505 for Satellite and Capsule 6.17 on RHEL 9, addressing 24 CVEs. The update fixes code execution, command injection, authorization bypass, information disclosure, SQL injection, cross-site scripting, and denial-of-service vulnerabilities.
Red Hat issued RHSA-2026:74504 for Satellite and Capsule 6.18 on RHEL 9, addressing 23 CVEs across Foreman, Katello, GitPython, Dynaconf, and other components. Fixes include the Viewer-role information disclosure, provisioning-token authentication bypass, Safemode bypass, and multiple command injection vulnerabilities.
The authorization vulnerability allows authenticated users with the Viewer role to retrieve sensitive host attributes, potentially including root passwords. Red Hat rated it Important with a CVSS v3 score of 9.1; command execution may also be possible if template Safemode protections are disabled or circumvented.
OSIDB Bzimport recorded a command injection vulnerability in the foreman-rake errors:fetch_log task, where request_id is interpolated into a shell command. A user with sudo permission to execute the task could run arbitrary code as the foreman user, potentially compromising managed infrastructure.
OSIDB Bzimport recorded a Foreman authentication-bypass vulnerability that checks a stored provisioning token's expiration rather than validating a requester-supplied token. Unauthenticated attackers could retrieve provisioning templates containing root password hashes, internal network information, and active build tokens.
Red Hat released fixes for Satellite 6.19 on RHEL 9 under advisory RHSA-2026:74503. The fixes address the Foreman template-preview authorization weakness that can expose sensitive host information to low-privileged authenticated users.
Red Hat addressed CVE-2026-33154 in Ansible Automation Platform 2.6 for RHEL 9 through advisory RHSA-2026:34160. The vulnerability permits arbitrary code execution through server-side template injection in Dynaconf.
Dynaconf version 3.2.13 patches CVE-2026-33154, an arbitrary code execution vulnerability caused by unsafe template evaluation in its @Jinja resolver. Earlier versions evaluate configuration template expressions without a sandbox when jinja2 is installed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcedocs.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.