Hi, A security fix has been released in Foreman Remote Execution, an open-source plugin for Foreman, an open-source lifecycle management tool for physical and virtual servers.
CVE-2026-12405: Foreman Remote Execution: command injection via effective_user An authenticated user with permission to execute job templates can inject commands through the overridable `effective_user` parameter during job invocation. Improper input handling allows command execution with the execution user's privileges on managed hosts. Affected versions: Foreman Remote Execution 0.1.2–16.6.5, 16.7.0, 17.0.0–17.2.1, and 18.0.0 CVSS: 8.8 (Important) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Fixed versions: Foreman Remote Execution 16.6.6, 17.2.2, and 18.0.1 Credit: Guilherme Suckevicz References: - Foreman Security: https://theforeman.org/security.html#2026-12405 - Redmine: https://projects.theforeman.org/issues/39836 - Fix: https://github.com/theforeman/foreman_remote_execution/pull/1072 Thanks, Ondrej Gajdusek Foreman Release Team
