
Foreman: 4 CVEs fixed in 3.18.2, 3.19.1 https://www.openwall.com/lists/oss-security/2026/07/07/7 CVE-2026-5136: Privilege escalation via usergroup role assignment CVE-2026-5142: Private SSH key disclosure CVE-2026-5135: Unauthorized modification of host configuration CVE-2026-5138: Information disclosure
Post summary
Foreman disclosed that four vulnerabilities—CVE‑2026‑5136, CVE‑2026‑5142, CVE‑2026‑5135, and CVE‑2026‑5138—have been patched in the 3.18.2 and 3.19.1 releases.
