In the foreman_ansible plugin component for Foreman in unpatched versions a medium severity vulnerability CVE-2026-92894 was detected. This vulnerability allows an authenticated attacker to delete arbitrary configuration override values. To address this issue, users should upgrade the foreman_ansible plugin to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-92894.
Read more IT Business ManagementIn foreman_ansible plugin component for Foreman in affected versions a medium severity vulnerability CVE-2026-92893 was detected. This vulnerability allows an attacker to bypass host view permissions and access restricted information. To address this issue, users should upgrade Foreman to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-92893.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a high severity vulnerability CVE-2026-5136 was detected. This vulnerability allows attackers to gain unintended role permissions. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5136.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a medium severity vulnerability CVE-2026-5135 was detected. This vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a different host. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5135.
Read more IT Business ManagementIn Foreman versions prior to 6.16.10 a medium severity vulnerability CVE-2026-5138 was detected. This vulnerability allows an authenticated user with host-edit permissions to access information from other tenants. To address this issue, users should upgrade Foreman to version 6.16.10 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-5138.
Read more IT Business ManagementIn Ansible Lightspeed all the versions a medium severity vulnerability CVE-2026-44188 was detected. This vulnerability allows a remote attacker to hijack a session and gain unauthorized read access to sensitive Ansible resources, such as inventories, playbooks, and configuration data. This occurs due to insufficient session expiration logic. If an attacker exfiltrates a valid OAuth access token before a user logs out, they can maintain persistent access because the backend application fails to properly invalidate the token upon logout, leaving it active until its natural expiration. There’s no fix available for this issue at the moment. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-44188.
Read more IT Business ManagementIn Ansible versions before 1.6.6 a medium severity vulnerability CVE-2014-3498 was detected. This vulnerability allows remote authenticated users to execute arbitrary commands due to a flaw in the user module. To address this issue, users should upgrade Ansible to version 1.6.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2014-3498.
Read more IT Business ManagementIn Ansible versions before 1.9.2 a high severity vulnerability CVE-2015-6240 was detected. This vulnerability allows local users to escape a restricted environment (such as a chroot, jail, or zone) via a symlink attack targeting the chroot, jail, and zone connection plugins. To address this issue, users should upgrade Ansible to version 1.9.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2015-6240.
Read more IT Business ManagementIn Ansible versions 2.3.x before 2.3.3 and 2.4.x before 2.4.1 a medium severity vulnerability CVE-2017-7550 was detected. This vulnerability allows remote attackers to expose sensitive information, such as passwords, from a remote host’s logs due to a flaw in how parameters are passed to the jenkins_plugin module’s “params” argument. To address this issue, users should upgrade Ansible to versions 2.3.3 or 2.4.1. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-7550.
Read more IT Business Management