Foreman
Vendor:
First CVE: Jul 31, 2013 · Active for 12 years
77
Total CVEs
More Total CVEs than 99% of tracked products
6.4
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Foreman over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 31, 2013
12 years ago
Most Recent CVE
Jul 1, 2026
23 days ago
CVE Severity & Scoring
Foreman77 CVEs
66%
27%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (9.1%)
Network44 (57.1%)
Unknown26 (33.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low44 (57.1%)
High7 (9.1%)
Unknown26 (33.8%)
User Interaction
None37 (48.1%)
Unknown26 (33.8%)
Required14 (18.2%)
Privileges Required
Low29 (37.7%)
High10 (13.0%)
None12 (15.6%)
Unknown26 (33.8%)
Top CVEs
Signals from CVEs in this product scope (77 CVEs).
77 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-2121MEDIUM Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to | Jul 31, 2013 | 6.0 | 45 | NO | YES |
CVE-2013-2113MEDIUM The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privil | Jul 31, 2013 | 6.0 | 43 | NO | YES |
CVE-2026-5136HIGH A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user wi | Jul 1, 2026 | 8.8 | 39 | NO | NO |
CVE-2014-0007HIGH The Smart-Proxy in Foreman before 1.4.5 and 1.5.x before 1.5.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path parameter to tftp/fetch_bo | Jun 20, 2014 | 7.5 | 38 | NO | YES |
CVE-2026-12112HIGH A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an | Jun 23, 2026 | 7.8 | 33 | NO | NO |
CVE-2018-14643CRITICAL An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machi | Sep 21, 2018 | 9.8 | 33 | NO | NO |
CVE-2026-5135MEDIUM A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a dif | Jul 1, 2026 | 6.5 | 32 | NO | NO |
CVE-2026-5142MEDIUM A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other o | Jul 1, 2026 | 6.5 | 32 | NO | NO |
CVE-2022-3874CRITICAL A command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile commands through CoreOS and Fedora | Sep 22, 2023 | 9.1 | 29 | NO | NO |
CVE-2026-9073MEDIUM A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs sessio | Jun 23, 2026 | 6.2 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (77 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
2.6% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
3.9% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (77 CVEs).
Media Mentions
Signals from CVEs in this product scope (77 CVEs).
Top CNAs Publishing CVEs For Foreman
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0.0 | 1 | 7.2 | 3.9% | 0 | 0 |
| 1.9.3 | 2 | 7.5 | 1.3% | 0 | 0 |
| 1.9.2 | 2 | 7.5 | 1.3% | 0 | 0 |
| 1.9.1 | 2 | 7.5 | 1.3% | 0 | 0 |
| 1.9.0 | 4 | 7.7 | 1.4% | 0 | 0 |
| 1.8.4 | 2 | 7.5 | 1.3% | 0 | 0 |
| 1.8.3 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.8.2 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.8.1 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.8.0 | 3 | 8.2 | 1.5% | 0 | 0 |
| 1.7.5 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.7.4 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.7.3 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.7.2 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.7.1 | 3 | 7.7 | 1.4% | 0 | 0 |
| 1.7.0 | 3 | 8.1 | 1.5% | 0 | 0 |
| 1.6.3 | 1 | 8.8 | 1.6% | 0 | 0 |
| 1.6.1 | 3 | 8.1 | 1.6% | 0 | 0 |
| 1.6.0 | 3 | 8.3 | 1.6% | 0 | 0 |
| 1.5.3 | 2 | 8.4 | 1.6% | 0 | 0 |