theforeman
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting theforeman.
- CVE-2026-5138Foreman: foreman: information disclosure via improper validation of nested request parameters4.3
- CVE-2026-5135Foreman: foreman: unauthorized modification of host configurations via broken access control6.5
- CVE-2026-5142Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass6.5
- CVE-2026-5136Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation8.8
- CVE-2026-13316Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config4.4
- CVE-2026-9073Foreman-mcp-server: mcp server: insecure sensitive http header sanitization6.2
- CVE-2026-12112Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse7.8
- CVE-2024-7700Foreman: command injection in "host init config" template via "install packages" field on foreman6.5
- CVE-2023-4886Foreman: world readable file containing secrets6.7
- CVE-2022-3874Os command injection via ct_command and fcct_command8.0
- CVE-2023-0462Arbitrary code execution through yaml global parameters8.0
- CVE-2023-0118Foreman: arbitrary code execution through templates9.1
- CVE-2021-20260A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulne...7.8
- CVE-2021-3590A flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output. The highest threat from this vulnerability is ...8.8
- CVE-2020-10710A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges...4.4