ZeroHour

Vulnerabilities

7 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-5136
+3 in the same advisory: …5142 …5135 …5138
A flaw was found in Foreman.

A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.

NVD description · AI analysis pending
8.8
group max
<1%
  • redhat satellite
  • redhat foreman
CVE-2026-13316
A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files.

A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Attackers can perform an SSRF attack and steal cloud metadata service on AWS/GCP/Azure environment through foreman component.

NVD description · AI analysis pending
4.4<1%
  • redhat satellite
  • redhat foreman
CVE-2026-12112
+1 in the same advisory: …9073
A flaw was found in the foreman-mcp-server.

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.

NVD description · AI analysis pending
7.8
group max
<1%
  • redhat satellite
  • redhat foreman