CVE-2026-92904
A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resol
CVSS
4.3
Medio
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Publicado: 17 sept 2026 · Última mod.: 18 sept 2026 · CWE-863
Sin historial EPSS suficiente todavía.
A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is restricted by a permission filter can enumerate job invocation IDs and read the live output, rendered script, and input values for other users' job invocations within their own organizations.