{"id":"CVE-2026-12541","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-12541","summary":"A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied…","details":"A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.","published":"2026-10-01T17:17:20.190","modified":"2026-10-02T17:17:05.660","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74503"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74504"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74505"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74506"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-12541"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489970"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T17:17:05.660"}}