
Foreman: 4 CVEs fixed in 3.18.2, 3.19.1 https://www.openwall.com/lists/oss-security/2026/07/07/7 CVE-2026-5136: Privilege escalation via usergroup role assignment CVE-2026-5142: Private SSH key disclosure CVE-2026-5135: Unauthorized modification of host configuration CVE-2026-5138: Information disclosure
Post summary
Foreman users should update to version 3.18.2 or 3.19.1 to address four CVEs, including privilege escalation, key disclosure, configuration tampering, and information disclosure.
