PT-2026-50457 · Red Hat · Red Hat Hardened Images+1
Published
2026-06-17
·
Updated
2026-06-17
·
CVE-2026-12515
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Katello of Red Hat Satellite (affected versions not specified)
Description
Insufficient authorization checks in the
ContentUploadsController within the content upload functionality allow authenticated users with the edit products permission to query content information for repositories they are not authorized to manage. This allows an attacker to determine if specific content exists within otherwise inaccessible repositories, although it does not permit unauthorized modification, import, or publication of content.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Hardened Images
Red Hat Satellite 6