CVE-2025-9572

MEDIUM

Foreman 1.22.0-3.16.1 - Incorrect Authorization via GraphQL API

Title source: llm
STIX 2.1

Description

n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:21886
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:21893
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:21894
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2025:21897
Vendor Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2025-9572
Vendor Advisory issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2391715

Scores

CVSS v3 5.0
EPSS 0.0001
EPSS Percentile 2.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (21)
Red Hat/Red Hat Satellite 6.15 for RHEL 8 0:3.9.1.14-1.el8sat
Red Hat/Red Hat Satellite 6.15 for RHEL 8 0:6.15.5.7-1.el8sat
Red Hat/Red Hat Satellite 6.16 for RHEL 8 0:3.12.0.12-1.el8sat
Red Hat/Red Hat Satellite 6.16 for RHEL 8 0:6.16.5.6-1.el8sat
Red Hat/Red Hat Satellite 6.16 for RHEL 9 0:3.12.0.12-1.el9sat
Red Hat/Red Hat Satellite 6.16 for RHEL 9 0:6.16.5.6-1.el9sat
Red Hat/Red Hat Satellite 6.17 for RHEL 9 0:3.14.0.11-1.el9sat
Red Hat/Red Hat Satellite 6.18 for RHEL 9 0:3.16.0.7-1.el9sat
Red Hat/Red Hat Satellite 6.18 for RHEL 9 0:4.18.0.4-1.el9sat
Red Hat/Red Hat Satellite 6.18 for RHEL 9 0:6.18.1-1.el9sat
... and 11 more
Published Feb 27, 2026
Tracked Since Feb 27, 2026