OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12541

HIGH · CVSS 8.2 EPSS 1.31%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A command injection vulnerability exists in the Foreman application, specifically within the foreman-rake db:dump and db:import_dump tasks, due to inadequate sanitization of user inputs in the destination and file parameters. This flaw allows an attacker with appropriate permissions to execute arbitrary shell commands, potentially compromising the system. Organizations using Foreman should prioritize patching this vulnerability to mitigate the risk of unauthorized command execution.

CVE
CVE-2026-12541
Severity
HIGH
CVSS
8.2
EPSS
1.31%

Original NVD Description

A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.