logo

High-Severity RCE Discovered in Foreman’s WebSocket Proxy

ID: 367c9f2d-8b6d-5829-a495-22d20def3ff8

STIX ID: report--367c9f2d-8b6d-5829-a495-22d20def3ff8

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed CVE-2026-1961, a high-severity command injection vulnerability in Foreman’s WebSocket proxy that allows remote code execution when unsanitized hostnames from compute resource providers (e.g., vSphere, Libvirt) are executed by the server; it affects Foreman up to 3.18.0 (CVSS 8.0) and is patched in 3.18.1, 3.17.2, and 3.16.3 — administrators are urged to update immediately to prevent full Foreman server compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.