Theforeman is a widely deployed open-source systems-management and provisioning platform that occupies a prominent niche in infrastructure automation, where its modular architecture spans core provisioning, configuration management via Ansible integration, and command-line tooling. Vulnerabilities affecting the vendor skew toward serious outcomes: a meaningful share reach critical severity, and the exposure recurs across the platform's web interfaces and plugin ecosystem through weakness classes including cross-site scripting, information exposure, and code injection that are characteristic of complex web-application frameworks handling sensitive infrastructure credentials and deployment logic. The vendor's product portfolio—encompassing Foreman itself, Katello package management, Foreman Ansible, Hammer CLI, and background-task handling—presents a broad attack surface centered on authentication, authorization, and input-handling boundaries in provisioning workflows. Defenders should prioritize patching this vendor's advisories in internet-reachable provisioning infrastructure, as exploitation of these weakness classes can compromise the integrity of deployed systems across an organization's estate; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Theforeman over time
Signals from CVEs in this vendor scope (98 CVEs).
98 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2143MEDIUM The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action, which allows remote authenticated users to ga | Apr 17, 2014 | 6.5 | 63 | NO | YES |
CVE-2013-2121MEDIUM Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to | Jul 31, 2013 | 6.0 | 45 | NO | YES |
CVE-2013-2113MEDIUM The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privil | Jul 31, 2013 | 6.0 | 43 | NO | YES |
CVE-2026-5136HIGH A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user wi | Jul 1, 2026 | 8.8 | 39 | NO | NO |
CVE-2014-0007HIGH The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_bo | Jun 20, 2014 | 7.5 | 38 | NO | YES |
CVE-2026-12112HIGH A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an | Jun 23, 2026 | 7.8 | 33 | NO | NO |
CVE-2018-14643CRITICAL An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machi | Sep 21, 2018 | 9.8 | 33 | NO | NO |
CVE-2026-5135MEDIUM A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a dif | Jul 1, 2026 | 6.5 | 32 | NO | NO |
CVE-2026-5142MEDIUM A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other o | Jul 1, 2026 | 6.5 | 32 | NO | NO |
CVE-2012-3503CRITICAL The installation script in Katello 1.0 and earlier does not properly generate the Application.config.secret_token value, which causes each default installation to have the same sec | Aug 25, 2012 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (98 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Theforeman.
Media articles that mention a CVE ID that affects a product developed by Theforeman — matched by CVE ID, not by vendor name.