Satellite
This hub aggregates every CVE we track for Satellite, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
231
CVEs tracked
26
Critical
58
High
4
In CISA KEV
Severity distribution
MEDIUM117HIGH58LOW30CRITICAL26
Monthly trend
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
3
3
4
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Satellite.
- CVE-2026-5138Foreman: foreman: information disclosure via improper validation of nested request parameters4.3
- CVE-2026-5135Foreman: foreman: unauthorized modification of host configurations via broken access control6.5
- CVE-2026-5142Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass6.5
- CVE-2026-5136Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation8.8
- CVE-2026-13316Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config4.4
- CVE-2026-9073Foreman-mcp-server: mcp server: insecure sensitive http header sanitization6.2
- CVE-2026-12112Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse7.8
- CVE-2026-48864Libsolv: heap buffer overflow in libsolv repopagestore via unchecked decompression of malicious .solv page data7.8
- CVE-2026-9149Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file6.5
- CVE-2026-9150Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sha384/sha512 checksums6.5
- CVE-2026-0980Rubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc username8.3
- CVE-2024-7923Puppet-pulpcore: an authentication bypass vulnerability exists in pulpcore9.8
- CVE-2024-7012Puppet-foreman: an authentication bypass vulnerability exists in foreman9.8
- CVE-2024-4812Katello: potential cross-site scripting exploit in ui4.8
- CVE-2024-3716Foreman-installer: candlepin database password being leaked to local users via the process list6.2
Product normalization is registry-driven with AI assist and human review. How it works