CVE-2026-56098 is an authorization bypass vulnerability in rubygem-katello's RegistryProxiesController. The registry_authorize filter detects unauthorized requests and invokes the unauthorized method but does not terminate execution because a return statement is missing. Execution falls through into subsequent business logic and database validation filters, producing differential responses that reveal internal instance state. An unprivileged attacker can use these responses to enumerate valid Users, Organizations, and Products across the entire instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authorization bypass and information disclosure vulnerability in rubygem-katello. The registry_authorize filter fails to stop execution after rejecting unauthorized requests, allowing subsequent business logic and database validation filters to run. An unprivileged attacker can use differential responses to enumerate valid Users, Organizations, and Products across the entire instance.
Improper authorization logic in Katello allows resource enumeration. Updated Katello packages are supplied in the advisory.
Improper authorization logic in Katello permits resource enumeration. The advisory supplies an updated rubygem-katello package.
Improper authorization logic in Katello allows resource enumeration. A security fix is included in the updated rubygem-katello packages.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.