Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Theforeman

First CVE: Aug 25, 2012Active for: 14 yearsTotal CVEs: 98
35.9
VTI Score
Medium

Theforeman is a widely deployed open-source systems-management and provisioning platform that occupies a prominent niche in infrastructure automation, where its modular architecture spans core provisioning, configuration management via Ansible integration, and command-line tooling. Vulnerabilities affecting the vendor skew toward serious outcomes: a meaningful share reach critical severity, and the exposure recurs across the platform's web interfaces and plugin ecosystem through weakness classes including cross-site scripting, information exposure, and code injection that are characteristic of complex web-application frameworks handling sensitive infrastructure credentials and deployment logic. The vendor's product portfolio—encompassing Foreman itself, Katello package management, Foreman Ansible, Hammer CLI, and background-task handling—presents a broad attack surface centered on authentication, authorization, and input-handling boundaries in provisioning workflows. Defenders should prioritize patching this vendor's advisories in internet-reachable provisioning infrastructure, as exploitation of these weakness classes can compromise the integrity of deployed systems across an organization's estate; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
98
Total CVEs
More Total CVEs than 99% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
6.2
Avg CVSS Score
Higher Avg CVSS Score than 36% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Theforeman over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 25, 2012
13 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (98 CVEs).

98 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-2143MEDIUM
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to ga
Apr 17, 20146.563NOYES
CVE-2013-2121MEDIUM
Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to
Jul 31, 20136.045NOYES
CVE-2013-2113MEDIUM
The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privil
Jul 31, 20136.043NOYES
CVE-2026-5136HIGH
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user wi
Jul 1, 20268.839NONO
CVE-2014-0007HIGH
The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_bo
Jun 20, 20147.538NOYES
CVE-2026-12112HIGH
A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an
Jun 23, 20267.833NONO
CVE-2018-14643CRITICAL
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machi
Sep 21, 20189.833NONO
CVE-2026-5135MEDIUM
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a dif
Jul 1, 20266.532NONO
CVE-2026-5142MEDIUM
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other o
Jul 1, 20266.532NONO
CVE-2012-3503CRITICAL
The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same sec
Aug 25, 20129.831NONO
View all 98 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products98 CVEs
65%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local13 (13.3%)
Network57 (58.2%)
Unknown28 (28.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low61 (62.2%)
High9 (9.2%)
Unknown28 (28.6%)
User Interaction
None53 (54.1%)
Unknown28 (28.6%)
Required17 (17.3%)
Privileges Required
Low43 (43.9%)
High12 (12.2%)
None15 (15.3%)
Unknown28 (28.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (98 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.1% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
4.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Theforeman.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Theforeman — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Theforeman's Products

View all 2 CNAs →

Top CWEs