Privilege Escalation: Auth User Deletes Ansible Override Values in Foreman Ans Plugin
CVE-2026-92894 Published on September 17, 2026
Rubygem-foreman_ansible: unscoped lookupvalue deletion allows cross-model override value destruction
A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user with the edit_ansible_variables permission can delete any LookupValue by ID, including override values for Ansible variables outside their permission filter scope and override values belonging to Puppet smart class parameters.
Vulnerability Analysis
CVE-2026-92894 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-92894 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-92894
Want to know whenever a new CVE is published for Red Hat Satellite? stack.watch will email you.