OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-96659

CRITICAL · CVSS 9.1 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical vulnerability exists in Foreman that enables authenticated users with low-level Viewer permissions to exploit template preview endpoints, leading to unauthorized information disclosure, including sensitive data like host root passwords. Additionally, in systems with Safemode protections disabled, this flaw could allow the execution of arbitrary commands as the Foreman system account. Organizations using Foreman, particularly those with misconfigured security settings, should prioritize addressing this vulnerability to mitigate potential data breaches and system compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96659
Severity
CRITICAL
CVSS
9.1
EPSS
0.32%

Original NVD Description

A flaw was found in Foreman. This vulnerability allows an authenticated user with low-level Viewer permissions to cause unauthorized information disclosure by submitting requests to template preview endpoints. By exploiting this issue, the user can access sensitive data, such as host root passwords. Furthermore, under insecure system configurations where Safemode protections are disabled, the flaw may allow the user to execute arbitrary commands as the Foreman system account.