Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-1961— Forman: foreman: remote code execution via command injection in websocket proxy

CVSS 8.0 · High EPSS 0.04% · P14
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-1961

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Forman: foreman: remote code execution via command injection in websocket proxy
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in Foreman. A remote attacker could exploit a command injection vulnerability in Foreman's WebSocket proxy implementation. This vulnerability arises from the system's use of unsanitized hostname values from compute resource providers when constructing shell commands. By operating a malicious compute resource server, an attacker could achieve remote code execution on the Foreman server when a user accesses VM VNC console functionality. This could lead to the compromise of sensitive credentials and the entire managed infrastructure.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Foreman 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Foreman是Foreman开源的一套用于物理和虚拟服务器中的生命周期管理工具。该工具提供服务开通、配置管理以及报告状态等功能。 Foreman存在安全漏洞,该漏洞源于WebSocket代理实现中的命令注入,当系统使用来自计算资源提供商的未清理主机名值构建shell命令时,攻击者通过操作恶意计算资源服务器,在用户访问VM VNC控制台功能时可能在Foreman服务器上实现远程代码执行,从而可能导致敏感凭据和整个托管基础设施被破解。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Red HatRed Hat Satellite 6.16 for RHEL 8 0:3.12.0.14-1.el8sat ~ * cpe:/a:redhat:satellite_utils:6.16::el8
Red HatRed Hat Satellite 6.16 for RHEL 9 0:3.12.0.14-1.el9sat ~ * cpe:/a:redhat:satellite_utils:6.16::el8
Red HatRed Hat Satellite 6.17 for RHEL 9 0:3.14.0.14-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.1.23-0.3.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:1.2.0-0.1.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:4.2.28-0.1.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:2.22.3-1.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:3.27.10-2.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:1.5.1-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.4.3-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:4.16.0.14-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.13.0-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:6.17.7-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.0.3-4.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:3.14.0.14-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.1.23-0.3.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:1.2.0-0.1.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:4.2.28-0.1.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:2.22.3-1.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:3.27.10-2.el9pc ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:1.5.1-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.4.3-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:4.16.0.14-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.13.0-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:6.17.7-1.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.17 for RHEL 9 0:0.0.3-4.el9sat ~ * cpe:/a:redhat:satellite:6.17::el9
Red HatRed Hat Satellite 6.18 for RHEL 9 0:3.16.0.12-1.el9sat ~ * cpe:/a:redhat:satellite_capsule:6.18::el9
Red HatRed Hat Satellite 6-cpe:/a:redhat:satellite:6

II. Public POCs for CVE-2026-1961

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-1961

登录查看更多情报信息。

Same Patch Batch · Red Hat · 2026-03-26 · 17 CVEs total

CVE-2025-128058.1 HIGHLlama-stack-k8s-operator: llama stack service exposed across namespaces due to missing net
CVE-2026-24366.5 MEDIUMLibsoup: libsoup: denial of service via use-after-free in soupserver during tls handshake
CVE-2026-31216.5 MEDIUMKeycloak: org.keycloak/keycloak-services: keycloak: privilege escalation via manage-client
CVE-2026-48876.1 MEDIUMGimp: gimp:memory disclosure and denial of service via specially crafted pcx image
CVE-2026-48975.5 MEDIUMPolkit: polkit: denial of service via unbounded input processing through standard input
CVE-2026-21005.3 MEDIUMP11-kit: null dereference via c_derivekey with specific null parameters
CVE-2026-22724.3 MEDIUMGimp: gimp: memory corruption due to integer overflow in ico file handling
CVE-2026-31904.3 MEDIUMKeycloak: keycloak: information disclosure via improper role enforcement in uma 2.0 protec
CVE-2026-22713.3 LOWGimp: gimp: denial of service via crafted psp image file
CVE-2026-09683.1 LOWLibssh: libssh: denial of service due to malformed sftp message
CVE-2026-48743.1 LOWOrg.keycloak.protocol.oidc.grants: org.keycloak.services.managers: keycloak: server-side r
CVE-2026-22392.8 LOWGimp: gimp: application crash (dos) via crafted psd file due to heap-buffer-overflow
CVE-2026-0965Libssh: libssh: denial of service via improper configuration file handling
CVE-2026-0967Libssh: libssh: denial of service via inefficient regular expression processing
CVE-2026-0964Libssh: improper sanitation of paths received from scp servers
CVE-2026-0966Libssh: buffer underflow in ssh_get_hexa() on invalid input

IV. Related Vulnerabilities

V. Comments for CVE-2026-1961

No comments yet


Leave a comment