CVE-2026-4324Disclosure

LOWCVSS 5.4 · MEDIUM

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort_by parameter of the /api/hosts/bootc_images API endpoint. This can lead to a Denial of Service (DoS) by triggering database errors, and potentially enable Boolean-based Blind SQL injection, which could allow an attacker to extract sensitive information from the database.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 5 mentions across 1 observed day

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-03-17: 5Technical Details · 2026-03-17: 503-17
Signal classification1 categories
Disclosure
5100.0%
Referenced assets5 URLs
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4324 A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to in… https://www.cve.org/CVERecord?id=CVE-2026-4324

    Post summary

    CVE-2026-4324 is a disclosed flaw in the Katello plugin for Red Hat Satellite, where improper input sanitization may enable remote attackers.

    00000118
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4324 - Rubygem-katello: katello: denial of service and potential information disclosure via sql injection Intel Report: https://ift.tt/rZBu8SR

    Post summary

    A new CVE (CVE-2026-4324) affecting Rubygem-katello has been announced, noting a denial-of-service condition and potential information disclosure through SQL injection, with an Intel Report linked for further details.

    0000067
    336 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4324 - Rubygem-katello: katello: denial of service and potential information disclosure via sql injection Intel Report: https://ift.tt/hQKJuSx

    Post summary

    The alert announces CVE‑2026‑4324 affecting rubygem‑katello, noting a denial‑of‑service condition and possible information disclosure via SQL injection, with no PoC, exploit code, or patch provided.

    0000036
    336 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4324 SQL Injection Vulnerability in Red Hat Satellite Katello Plugin via Hosts API Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4324

    Post summary

    Reports the discovery of an SQL injection flaw in Red Hat Satellite Katello Plugin’s Hosts API endpoint associated with CVE-2026-4324.

    0000058
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4324 - Rubygem-katello: katello: denial of service and potential information disclosure via sql injection Intel Report: https://ift.tt/e4uL6lb

    Post summary

    The alert identifies CVE‑2026‑4324 as a SQL injection‑based denial‑of‑service vulnerability in Rubygem‑katello, but does not mention any PoC, exploit tool, active exploitation, or patch availability.

    0000028
    336 followersView on X

Explore more