CVE-2026-12405 is a command-injection vulnerability in rubygem-foreman_remote_execution affecting Red Hat Satellite's job-invocation API. When a job template permits overriding the effective_user property, the application fails to properly sanitize the value supplied in an API request. An authenticated attacker authorized to execute job templates can inject arbitrary shell commands during the Satellite server's instantiation of the job execution environment. Exploitation is independent of the template or playbook content, and injected commands execute on target infrastructure with the privileges of the job execution user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity command-injection flaw in rubygem-foreman_remote_execution used by Red Hat Satellite. A user permitted to execute job templates can inject shell commands through an overridable effective_user API parameter; the commands execute on target infrastructure with the execution user's privileges.
The effective_user parameter in Foreman Remote Execution job invocations allows command injection. Updated rubygem-foreman_remote_execution packages address the flaw.
Command injection vulnerability in Foreman Remote Execution job invocations involving the effective_user parameter. The advisory supplies an updated rubygem-foreman_remote_execution package.
The effective_user parameter permits command injection in job invocations handled by foreman_remote_execution. Updated packages are supplied in the advisory.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.