CyberRota
← Ana sayfaya dön

CVE-2026-5142

MEDIUM · CVSS 6.5

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-01T15:17:11.977 · Çekilme zamanı: 2026-07-01T18:37:13.303427+00:00

CyberRota Yorumu

Saldırganın giriş yapmış olması gerekebilir.

CVE
CVE-2026-5142
Severity
MEDIUM
CVSS
6.5
EPSS
Yok

Orijinal NVD Açıklaması

A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other organizations by directly querying key pair IDs. This vulnerability leads to cross-tenant data exposure in multi-tenant deployments, potentially compromising sensitive information.