PT-2026-50457 · Red Hat · Red Hat Hardened Images+1

Published

2026-06-17

·

Updated

2026-06-17

·

CVE-2026-12515

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Katello of Red Hat Satellite (affected versions not specified)
Description Insufficient authorization checks in the ContentUploadsController within the content upload functionality allow authenticated users with the edit products permission to query content information for repositories they are not authorized to manage. This allows an attacker to determine if specific content exists within otherwise inaccessible repositories, although it does not permit unauthorized modification, import, or publication of content.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12515

Affected Products

Red Hat Hardened Images
Red Hat Satellite 6