OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-12544

HIGH · CVSS 7.7 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The vulnerability in Foreman arises from flawed initialization logic in the configuration settings, which allows for Server-Side Template Injection (SSTI) and insecure deserialization through a multi-stage execution chain. This can result in remote code execution, potentially leading to total infrastructure compromise and significant supply chain risks. Organizations using Foreman should prioritize patching this vulnerability to mitigate the high risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12544
Severity
HIGH
CVSS
7.7
EPSS
0.22%

Original NVD Description

A flaw was found in Foreman. The foreman-rake initialization logic in /usr/share/foreman/config/settings.rb contains a vulnerable code pattern where configuration data is processed through two distinct executable layers. This creates a multi-stage execution chain that allows for both Server-Side Template Injection (SSTI) and insecure deserialization. This vulnerability can lead to remote code execution, total infrastructure compromise and supply chain risk.