Foreman Ansible Plugin: Unscoped Host Query Exposes Hidden Parameters
CVE-2026-92893 Published on September 17, 2026

Rubygem-foreman_ansible: ansible inventory api ignores view_hosts permission filters, exposes hidden parameters
A flaw was found in the foreman_ansible plugin's Ansible inventory API. The controller builds its host query using an unscoped Host.where call that does not enforce the search filter associated with the caller's view_hosts permission. An authenticated user whose host visibility is restricted by a permission filter can supply arbitrary host IDs within their organization and receive the full Ansible inventory for those hosts, including parameter values marked as hidden.

NVD

Vulnerability Analysis

CVE-2026-92893 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
LOW
Integrity Impact:
NONE
Availability Impact:
NONE

Timeline

Reported to Red Hat.

Made public.

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-92893 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-92893

Want to know whenever a new CVE is published for Red Hat Satellite? stack.watch will email you.

 

Affected Versions

Red Hat Satellite 6: