<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T02:41:53.940252+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-277086</id>
    <title>EUVD-2026-277086</title>
    <updated>2026-10-05T02:41:53.947505+00:00</updated>
    <content>EUVD-2026-277086</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-277086"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9572</id>
    <title>fkie_cve-2025-9572</title>
    <updated>2026-10-05T02:41:53.947539+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-9572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gvvp-xfg4-2fr6</id>
    <title>GHSA-gvvp-xfg4-2fr6</title>
    <updated>2026-10-05T02:41:53.947570+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gvvp-xfg4-2fr6"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:21886</id>
    <title>RHSA-2025:21886 — Red Hat Security Advisory: Satellite 6.18.1 Async Update</title>
    <updated>2026-10-05T02:41:53.947588+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>foreman: Satellite: GraphQL API permission bypass leads to information disclosure</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:21886"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9572</id>
    <title>UBUNTU-CVE-2025-9572</title>
    <updated>2026-10-05T02:41:53.947606+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: ruby-foreman, Ubuntu:18.04:LTS: ruby-foreman, Ubuntu:20.04:LTS: ruby-foreman, Ubuntu:22.04:LTS: ruby-foreman, Ubuntu:24.04:LTS: ruby-foreman, Ubuntu:25.10: ruby-foreman, Ubuntu:26.04:LTS: ruby-foreman</p>
<p>n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9572"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2652</id>
    <title>WID-SEC-W-2025-2652 — Red Hat Satellite: Schwachstelle ermöglicht Offenlegung von Informationen</title>
    <updated>2026-10-05T02:41:53.947635+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter Angreifer kann eine Schwachstelle in Red Hat Satellite für Red Hat Enterprise Linux ausnutzen, um Sicherheitsmaßnahmen zu umgehen und so vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2652"/>
  </entry>
</feed>
