{"id":"CVE-2026-12423","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-12423","summary":"A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The…","details":"A flaw was found in Foreman. The Red Hat Satellite /unattended/provision API endpoint is vulnerable to an authentication bypass due to a semantic logic flaw in host_verifier.rb. The application verifies the database state of a provisioning token rather than its actual presence in the incoming HTTP request. Because a host actively undergoing provisioning has an unexpired token in the database, the server's valid_host_token? method evaluates to true, granting access to the kickstart template even if the requester provides no token at all in the URL.","published":"2026-10-01T17:17:19.887","modified":"2026-10-02T17:17:05.383","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74503"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74504"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74505"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74506"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-12423"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2488956"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T17:17:05.383"}}