Hi,

A security fix has been released in Katello, a content management plugin for
Foreman.

CVE-2026-56098: Katello: Registry Proxy authorization bypass

An authenticated low-privilege user can bypass Registry Proxy authorization
checks and enumerate organizations and products through response differences.

Affected versions: Katello 4.13.0 through 4.21.1.1, and 5.0.0
CVSS: 4.3 (Moderate)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Fixed versions: Katello 4.21.2 and 5.0.1
Credit: Guilherme Suckevicz

References:
- Foreman Security: https://theforeman.org/security.html#2026-56098
- Redmine: https://projects.theforeman.org/issues/39844
- Fix: https://github.com/Katello/katello/pull/11887

Thanks,
Ondrej Gajdusek
Foreman Release Team

Reply via email to