OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12540

HIGH · CVSS 8.2 EPSS 1.31%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A command injection vulnerability in the foreman-rake errors:fetch_log task allows attackers with sudo permissions to exploit the request_id parameter, enabling them to inject shell metacharacters and execute arbitrary code. This high-severity flaw poses a significant risk to systems using Foreman, particularly those where users have elevated privileges. Organizations utilizing Foreman should prioritize patching this vulnerability to mitigate potential exploitation.

CVE
CVE-2026-12540
Severity
HIGH
CVSS
8.2
EPSS
1.31%

Original NVD Description

A flaw was found in Foreman. A command injection vulnerability exists in the foreman-rake errors:fetch_log task. The request_id parameter is passed to an underlying system command (typically grep) without adequate shell neutralization. While the task is intended to fetch specific log entries, an attacker with sudo permissions to execute this rake task can inject shell metacharacters (such as ;, ", or |) to break out of the intended command and execute arbitrary code.