<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 17:39:23 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-332121</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-332121</link>
      <description>EUVD-2026-332121</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-332121</guid>
    </item>
    <item>
      <title>fkie_cve-2026-5136</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-5136</link>
      <description>&lt;p&gt;A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user&amp;#39;s permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user&amp;#39;s permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-5136</guid>
    </item>
    <item>
      <title>GHSA-fpxf-rppp-4373</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fpxf-rppp-4373</link>
      <description>&lt;p&gt;A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user&amp;#39;s permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user&amp;#39;s permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fpxf-rppp-4373</guid>
    </item>
    <item>
      <title>RHSA-2026:34365 — Red Hat Security Advisory: Satellite 6.19.2 Async Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:34365</link>
      <description>&lt;p&gt;foreman: Foreman: Unauthorized modification of host configurations via broken access control foreman: Foreman: Privilege escalation to administrator-level access via usergroup role assignment manipulation foreman: Foreman: Information disclosure via improper validation of nested request parameters foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass net/url: Incorrect parsing of IPv6 host literals in net/url com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;foreman: Foreman: Unauthorized modification of host configurations via broken access control foreman: Foreman: Privilege escalation to administrator-level access via usergroup role assignment manipulation foreman: Foreman: Information disclosure via improper validation of nested request parameters foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass net/url: Incorrect parsing of IPv6 host literals in net/url com.mchange/mchange-commons-java: mchange-commons-java: Arbitrary code execution via JNDI dereferencing of crafted objects crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:34365</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2166 — Red Hat Satellite (foreman, python-pillow, go): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2166</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um sich erweiterte Rechte, einschließlich Administratorrechte, zu verschaffen, die Authentifizierung zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Satellite ausnutzen, um sich erweiterte Rechte, einschließlich Administratorrechte, zu verschaffen, die Authentifizierung zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen und einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2166</guid>
    </item>
  </channel>
</rss>
