In the foreman_ansible plugin component for Foreman in unpatched versions a medium severity vulnerability CVE-2026-92894 was detected. This vulnerability allows an authenticated attacker to delete arbitrary configuration override values. To address this issue, users should upgrade the foreman_ansible plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-92894.
Read more IT Business ManagementIn foreman_ansible plugin component for Foreman in affected versions a medium severity vulnerability CVE-2026-92893 was detected. This vulnerability allows an attacker to bypass host view permissions and access restricted information. To address this issue, users should upgrade Foreman to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-92893.
Read more IT Business ManagementIn Kimai versions prior to 2.58.0 a medium severity vulnerability CVE-2026-52823 was detected. This vulnerability allows an attacker to perform unauthorized actions by tricking an authenticated user into visiting a malicious link. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-52823.
Read more Project ManagementIn Kimai versions 2.65.0 and earlier a medium severity vulnerability CVE-2026-84804 was detected. This vulnerability allows authenticated users to bypass authorization controls. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84804.
Read more Project ManagementIn Kimai versions from 2.61.0 before 2.63.0 a medium severity vulnerability CVE-2026-84805 was detected. This vulnerability allows an authenticated regular user to use the API to modify their own admin-only work-contract data. To address this issue, users should upgrade Kimai to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-84805.
Read more Project ManagementIn Foreman versions prior to 6.16.10 a high severity vulnerability CVE-2026-5136 was detected. This vulnerability allows attackers to gain unintended role permissions. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5136.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a medium severity vulnerability CVE-2026-5135 was detected. This vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5135.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a medium severity vulnerability CVE-2026-5138 was detected. This vulnerability allows an authenticated user with host-edit permissions to access information from other tenants. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5138.
Read more IT Business ManagementIn Ansible Lightspeed all the versions a medium severity vulnerability CVE-2026-44188 was detected. This vulnerability allows a remote attacker to hijack a session and gain unauthorized read access to sensitive Ansible resources, such as inventories, playbooks, and configuration data. This occurs due to insufficient session expiration logic. If an attacker exfiltrates a valid OAuth access token before a user logs out, they can maintain persistent access because the backend application fails to properly invalidate the token upon logout, leaving it active until its natural expiration. There’s no fix available for this issue at the moment. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44188.
Read more IT Business Management