Low-priv template editors can root your Satellite host

By George Bailey   Published: 10/02/26   3 min read

Red Hat disclosed a critical Foreman templating flaw on October 1: an authenticated user with low privileges can bypass the safemode sandbox and run arbitrary commands on the Satellite host. CVSS 9.9. Errata are out for Satellite 6.16 / 6.18 / 6.19 trains.

If your build or provisioning stack runs on Satellite, Friday’s check is simple — who can edit templates, and are you on the fixed packages?

Template editors should not equal root on the provisioning host. Safemode exists so that sentence stays true.

What happened

CVE-2026-96658 is a safemode bypass in Foreman’s templating engine (CWE-94). Improper handling of delegated methods lets an authenticated low-privilege attacker append unauthorized functions to the allowed execution list and run arbitrary commands on the hosting server. Red Hat rates the impact Critical (CVSS 9.9, scope changed).

Affected products include Red Hat Satellite 6.16 (RHEL 8/9), 6.18 (RHEL 9), and 6.19 (RHEL 9), including Satellite, Capsule, and Utils components. Remediation is via Red Hat errata RHSA-2026:74503 (and related 74504 / 74506). Fixed package versions include builds such as 0:3.18.0.14-1.el9sat on the 6.19 train — apply the matching RHSA for your release. No public PoC and not on KEV at publish time.

Why it matters

Satellite / Foreman is the provisioning and configuration control plane. RCE on that host is RCE across every system it builds, patches, or remediates. The privilege bar is low — baseline template access, not full admin — which widens the insider and compromised-account blast radius.

What to do first

Forward this

If you own Red Hat Satellite / Foreman: a low-privilege template editor can bypass safemode and get RCE on the host (CVE-2026-96658). Please confirm RHSA-2026:74503 (and related errata) are applied, template-editor roles are minimized, and recent template changes were reviewed.

Details

Hunt / verify

Slack paste: Foreman/Satellite CVE-2026-96658 safemode RCE — apply RHSA-2026:74503, lock down template editors, audit recent template changes.

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.