CVE-2026-71458
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 s
CVSS
5.0
Medium
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Published: Sep 23, 2026 · Last modified: Sep 24, 2026 · CWE-204
URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403→404 shim only rewrites 403 responses, leaving the pk=0 miss path with a different 404 detail string. Differential "Not found." vs "No <Model> matches..." reveals whether a named resource (org, credential, inventory, host) exists anywhere on the platform. Enables cross-tenant internal hostname enumeration.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71113
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71114
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71177
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:71179
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2026-71458
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2512367