CVE-2026-12542

MEDIUM CVSS 3.1: 5.3 EPSS 0.55%
Updated Oct 02, 2026
Red Hat
Parameter Value
CVSS 5.3 (MEDIUM)
Type CWE-78 (OS Command Injection)
Vendor Red Hat
Public PoC No

A flaw was found in Foreman. The foreman-tail utility is vulnerable to OS command injection due to the unsafe use of the eval command. The script takes user-supplied arguments and incorporates them directly into a string that is then executed by eval to expand file paths.

Because the input is not sanitized or quoted, a local attacker can inject shell metacharacters (e.g., ;, &, |) to execute arbitrary system commands.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products

red hat:red hat satellite 6.18 for rhel 9 red hat:red hat satellite 6.16 for rhel 8 red hat:red hat satellite 6.16 for rhel 9 red hat:red hat satellite 6.19 for rhel 9 red hat:red hat satellite 6