CVE-2026-79654

medium

Description

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.

References

https://projects.theforeman.org/issues/39701

https://github.com/Katello/katello/pull/11847

https://bugzilla.redhat.com/show_bug.cgi?id=2523348

https://access.redhat.com/security/cve/CVE-2026-79654

Details

Source: Mitre, NVD

Published: 2026-08-26

Updated: 2026-08-28

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00269