{"id":"CVE-2026-12544","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-12544","summary":"A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed…","details":"A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.","published":"2026-10-01T17:17:20.340","modified":"2026-10-02T17:17:05.803","cvss":{"score":7.7,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74503"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74504"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74505"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2026:74506"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-12544"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489992"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-02T17:17:05.803"}}