Red Hat disclosed a critical Foreman templating flaw on October 1: an authenticated user with low privileges can bypass the safemode sandbox and run arbitrary commands on the Satellite host. CVSS 9.9. Errata are out for Satellite 6.16 / 6.18 / 6.19 trains.
If your build or provisioning stack runs on Satellite, Friday’s check is simple — who can edit templates, and are you on the fixed packages?
Template editors should not equal root on the provisioning host. Safemode exists so that sentence stays true.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
CVE-2026-96658 is a safemode bypass in Foreman’s templating engine (CWE-94). Improper handling of delegated methods lets an authenticated low-privilege attacker append unauthorized functions to the allowed execution list and run arbitrary commands on the hosting server. Red Hat rates the impact Critical (CVSS 9.9, scope changed).
Affected products include Red Hat Satellite 6.16 (RHEL 8/9), 6.18 (RHEL 9), and 6.19 (RHEL 9), including Satellite, Capsule, and Utils components. Remediation is via Red Hat errata RHSA-2026:74503 (and related 74504 / 74506). Fixed package versions include builds such as 0:3.18.0.14-1.el9sat on the 6.19 train — apply the matching RHSA for your release. No public PoC and not on KEV at publish time.
Why it matters
Satellite / Foreman is the provisioning and configuration control plane. RCE on that host is RCE across every system it builds, patches, or remediates. The privilege bar is low — baseline template access, not full admin — which widens the insider and compromised-account blast radius.
What to do first
- Apply the RHSA. Install RHSA-2026:74503 (and companion errata for Capsule/Utils) on every Satellite / Capsule.
- Shrink template privileges. Limit who can create or edit templates; remove unused template-editor roles.
- Audit recent template changes. Review edits since before the advisory for unexpected delegated methods or shell callouts.
- Keep safemode on. Do not disable the sandbox as a “fix.”
Forward this
If you own Red Hat Satellite / Foreman: a low-privilege template editor can bypass safemode and get RCE on the host (CVE-2026-96658). Please confirm RHSA-2026:74503 (and related errata) are applied, template-editor roles are minimized, and recent template changes were reviewed.
Details
- CVE: CVE-2026-96658 (Foreman safemode bypass → RCE)
- Impact: Authenticated low-priv RCE on Satellite / Foreman host via templating
- CVSS: 9.9 (Red Hat)
- Errata: RHSA-2026:74503 / 74504 / 74506 (Oct 1, 2026)
- Affected: Satellite 6.16 / 6.18 / 6.19 (Satellite, Capsule, Utils as listed)
- Privileges required: Low (authenticated)
Hunt / verify
- Confirm Satellite packages match the fixed RHSA builds for your train.
- List users with template create/edit permissions; remove stale accounts.
- Diff production templates against known-good revisions for shell / unsafe delegations.
Slack paste: Foreman/Satellite CVE-2026-96658 safemode RCE — apply RHSA-2026:74503, lock down template editors, audit recent template changes.
Sources
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.