CVE-2026-1961Disclosure

MEDIUMCVSS 8.0 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-30); latest day: 1
  • 6 total mentions across 5 days

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-03-26: 1Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Mentions · 2026-03-30: 2Mentions · 2026-09-18: 1PoC Mentioned / Linked · 2026-09-18: 1Exploit Tool / Code · 2026-09-18: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-09-18: 1Technical Details · 2026-03-26: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 1Technical Details · 2026-03-30: 2Technical Details · 2026-09-18: 103-2603-2803-2903-3009-18
Signal classification3 categories
Disclosure
350.0%
Patch
233.3%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-261
Disclosure1
2026-03-281
Patch1
2026-03-291
Disclosure1
2026-03-302
Disclosure1Patch1
2026-09-181
PoC1
Full discourse6 posts
  • Gray Hats@the_yellow_fall
    Patch

    Foreman patches a critical 8.0 CVSS command injection flaw (CVE-2026-1961). Malicious hostnames can trigger RCE via WebSocket proxies. Update to 3.18.1 now! #Foreman #CyberSecurity #InfoSec #RCE #SysAdmin #Automation #Vulnerability #CloudSecurity #Linux https://securityonline.info/foreman-rce-vulnerability-cve-2026-1961-command-injection/ https://t.co/vt0hHOFOK1

    Post summary

    The post announces that Foreman has released a critical patch (v3.18.1) for CVE‑2026‑1961, a command injection vulnerability leading to remote code execution, with no indication of existing exploits or active attacks.

    04053678
    12.3K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-1961: Foreman: Remote Code Execution via command injection in WebSocket proxy https://www.openwall.com/lists/oss-security/2026/03/27/3 when constructing shell commands using unsanitized hostname values from compute resource providers (VMware vSphere, Libvirt, etc.) Fixed in 3.18.1, 3.17.2, 3.16.3

    Post summary

    The post announces a remote code execution vulnerability in Foreman’s WebSocket proxy, provides technical details on how unsanitized hostnames lead to command injection, and notes that the issue is fixed in versions 3.18.1, 3.17.2, and 3.16.3.

    01081791
    4.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 Foreman'da kritik RCE açığı için PoC yayınlandı! CVE-2026-1961 (CVSS 8.0), Foreman'ın WebSocket proxy bileşenindeki (lib/ws_proxy.rb) OS Command Injection açığını kullanarak sunucuda komut çalıştırılmasına izin veriyor. Saldırganın kontrol ettiği/sahtelediği bir VMware/vSphere sunucusundan gönderilen kötü amaçlı hostname, Foreman tarafından temizlenmeden işletim sistemi komutuna eklenebiliyor. Bir yönetici VM'nin Console özelliğini açtığında saldırganın komutları Foreman sunucusunda foreman kullanıcısı yetkileriyle çalıştırılabiliyor. Açık Foreman 3.18.0 ve öncesini etkiliyor. 3.18.1, 3.17.2 ve 3.16.3 sürümlerinde giderildi. Public PoC ise yayınlandı. PoC: https://github.com/kalnux/CVE-2026-1961-foreman-poc Advisory: https://access.redhat.com/security/cve/cve-2026-196

    Post summary

    The text announces a critical RCE vulnerability in Foreman (CVE-2026-1961) and provides a link to a public PoC, along with fixed versions and technical details.

    01044741
    2.4K followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    High-Severity RCE Discovered in Foreman’s WebSocket Proxy https://securityonline.info/foreman-rce-vulnerability-cve-2026-1961-command-injection/

    Post summary

    The text announces a newly discovered high‑severity RCE vulnerability (CVE‑2026‑1961) in Foreman's WebSocket Proxy, referencing a source URL for additional details.

    0000046
    244 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1961 A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises fr… https://www.cve.org/CVERecord?id=CVE-2026-1961

    Post summary

    The text announces a command‑injection vulnerability in Foreman’s WebSocket proxy, providing only technical details without any PoC, exploit code, or patch information.

    00000369
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1961 - High A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of u... https://www.thehackerwire.com/vulnerability/CVE-2026-1961/ https://t.co/5l21zOSMdG

    Post summary

    A new high‑severity command injection flaw in Foreman's WebSocket proxy is described, but no PoC, exploit, active exploitation, or patch details are provided.

    0000043
    163 followersView on X

Explore more