CVE-2025-46811 is a critical missing-authentication vulnerability in SUSE Manager affecting the WebSocket endpoint used for remote command execution on managed clients. The vulnerable endpoint, /rhn/websocket/minion/remote-commands, fails to enforce authentication before accepting command requests. As a result, any party able to reach the SUSE Manager HTTPS service on port 443 can interact with this endpoint and trigger execution of arbitrary commands as root on managed clients. The flaw affects multiple SUSE Manager 4.3 and 5.0 deployments, including server modules, cloud images, and containerized installations. The issue stems from exposure of a critical administrative function without required authentication checks.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is not a standalone exploit tool; it is an Ansible-based lab/challenge environment that deploys and wires together the vulnerable conditions for CVE-2025-46811 exploitation and a follow-on privilege-escalation path. The structure is centered around site.yml and multiple Ansible roles: host_requirements prepares the openSUSE host, uyuni_server builds and installs a custom Uyuni server container stack, leap_minion deploys a managed Salt minion container, uyuni_login deploys a Playwright-based browser automation container that periodically logs into the Uyuni web UI, and cleanup tears the environment down. The main exploit-relevant capability described by the repository is a two-stage compromise chain. Stage 1 is initial access via the Uyuni remote-command WebSocket endpoint associated with CVE-2025-46811, described in the documentation as the foothold into the management plane. The actual vulnerable WebSocket exploit code is not present here; instead, the repo provisions the target environment in which that vulnerability exists. Stage 2 is implemented directly in repository code: src/uyuni-server/maintenance.sh runs every 5 minutes via systemd timer and uses Salt to query the leap-minion for updates, writes package data into shared logs, extracts package names from the log, and then unsafely executes a Salt command through eval: eval "/usr/bin/salt 'leap-minion' cmd.run 'zypper update --no-confirm $packages'". Because package/log-derived content can be attacker-controlled through the shared writable log volume, this creates a command-injection privilege-escalation path on the uyuni-server container. Operationally, the environment exposes several notable targets and services: the Uyuni web login at https://uyuni-server/rhn/manager/login for simulated operator activity, SSH from the uyuni-server container published on host TCP port 2222, and shared volumes mounted at /srv/shared-data and /srv/shared-data/logs between containers. The maintenance timer/service units are bind-mounted into the uyuni-server container and enabled after minion registration. The leap-minion container is privileged, attached to the internal Podman network uyuni, and bootstrapped using files copied from the Uyuni server. Firewall rules are added with nftables to restrict container egress while preserving internal communication. Repository languages are primarily YAML/Ansible, Bash, Python, and Dockerfiles. Key exploit-relevant files are src/uyuni-server/maintenance.sh, roles/uyuni_login/templates/login.py.j2, roles/uyuni_server/tasks/*.yml, and roles/leap_minion/tasks/main.yml. Overall, the repository’s purpose is to reproducibly deploy a realistic vulnerable Uyuni/SaltStack containerized environment for security research or CTF-style exploitation, culminating in root access to the uyuni-server container.
This repository provides a fully functional exploit for CVE-2025-46811, a critical unauthenticated remote code execution vulnerability in SUSE Manager. The main exploit script (CVE-2025-46811.py) is a Python 3 tool that can scan multiple targets for vulnerability, execute arbitrary shell commands as root, and provide an interactive shell over a WebSocket connection to the endpoint '/rhn/websocket/minion/remote-commands'. The exploit bypasses SSL certificate verification and does not require authentication. The YAML file (CVE-2025-46811.yaml) describes the vulnerability in a format suitable for automated scanners (e.g., Nuclei), specifying the endpoints and the exploitation steps. The repository also includes a README with usage instructions, a list of example target IPs (ip.txt), and a standard MIT license. The exploit is operational, providing both detection and exploitation capabilities, and is intended for authorized penetration testing of SUSE Manager instances.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated remote command execution vulnerability in the remote-commands websocket endpoint that allows root command execution on clients.
A critical missing authentication vulnerability in SUSE Manager that allows remote unauthenticated attackers to execute arbitrary commands as root via the /rhn/websocket/minion/remote-commands websocket endpoint.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.