PT-2026-25899 · Red Hat · Red Hat Satellite 6
Published
2026-03-17
·
Updated
2026-03-17
·
CVE-2026-4324
CVSS v3.1
5.4
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L |
A flaw was found in the Katello plugin for Red Hat Satellite. This vulnerability, caused by improper sanitization of user-provided input, allows a remote attacker to inject arbitrary SQL commands into the sort by parameter of the /api/hosts/bootc images API endpoint. This can lead to a Denial of Service (DoS) by triggering database errors, and potentially enable Boolean-based Blind SQL injection, which could allow an attacker to extract sensitive information from the database.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Satellite 6