CVE-2026-12112Disclosure(redhat / foreman)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without re-validating authentication tokens and by logging all newly created session IDs to standard logs. This issue can result in privilege escalation and infrastructure-wide code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • foreman
  • satellite

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-06-24); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
foremansatellite

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-24: 1Mentions · 2026-07-30: 1Technical Details · 2026-07-30: 106-2407-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    CVE-2026-12112 is live. If you run affected systems, read this now. A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthen... New week. Sharper than the last.

    Post summary

    CVE‑2026‑12112 describes a session‑management flaw in foreman‑mcp‑server allowing unauthenticated access; no PoC, exploit tools, active exploitation, or patch information are provided.

    0000052
    336 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for Red Hat Satellite (CVE-2026-12112) https://vuldb.com/vuln/372993

    Post summary

    A severe vulnerability (CVE-2026-12112) in Red Hat Satellite has been publicly disclosed, linked to a vulnerability database entry, with no further exploitation or mitigation details shared.

    0000092
    2.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appredhatsatellite6.19--
Apptheforemanforeman---

Explore more