Foreman Remote Exec Plugin: Unchecked Permission Filter Exposes Job Invocations
CVE-2026-92904 Published on September 17, 2026
Rubygem-foreman_remote_execution: job output readable without object-level view_job_invocations check
A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is restricted by a permission filter can enumerate job invocation IDs and read the live output, rendered script, and input values for other users' job invocations within their own organizations.
Vulnerability Analysis
CVE-2026-92904 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-92904 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-92904
Want to know whenever a new CVE is published for Red Hat Satellite? stack.watch will email you.