Foreman
This hub aggregates every CVE we track for Foreman, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
79
CVEs tracked
2
Critical
23
High
0
In CISA KEV
Severity distribution
MEDIUM53HIGH23CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
3
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Foreman.
- CVE-2026-5138Foreman: foreman: information disclosure via improper validation of nested request parameters4.3
- CVE-2026-5135Foreman: foreman: unauthorized modification of host configurations via broken access control6.5
- CVE-2026-5142Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass6.5
- CVE-2026-5136Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation8.8
- CVE-2026-13316Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config4.4
- CVE-2026-9073Foreman-mcp-server: mcp server: insecure sensitive http header sanitization6.2
- CVE-2026-12112Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse7.8
- CVE-2025-9572Foreman: satellite: graphql api permission bypass leads to information disclosure5.0
- CVE-2025-10622Foreman: os command injection via ct_location and fcct_location parameters8.0
- CVE-2024-7700Foreman: command injection in "host init config" template via "install packages" field on foreman6.5
- CVE-2023-4886Foreman: world readable file containing secrets6.7
- CVE-2022-3874Os command injection via ct_command and fcct_command8.0
- CVE-2023-0462Arbitrary code execution through yaml global parameters8.0
- CVE-2023-0118Foreman: arbitrary code execution through templates9.1
- CVE-2021-20260A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulne...7.8
Product normalization is registry-driven with AI assist and human review. How it works