Red Hat Product Errata RHSA-2026:34368 - Security Advisory Issued: 2026-07-01 Updated: 2026-07-01 RHSA-2026:34368 - Security Advisory Overview Updated Packages Synopsis Important: Satellite 6.18.7 Async Update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic A new release is now available for Red Hat Satellite 6.18 for RHEL 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Red Hat Satellite is a system management solution that allows organizations to configure and maintain their systems without the necessity to provide public Internet access to their servers or other client systems. It performs provisioning and configuration management of predefined standard operating environments. Security Fix(es): foreman: Unauthorized modification of host configurations via broken access control (CVE-2026-5135) foreman: Privilege escalation to administrator-level access via usergroup role assignment manipulation (CVE-2026-5136) foreman: Information disclosure via improper validation of nested request parameters (CVE-2026-5138) foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass (CVE-2026-5142) yggdrasil-worker-forwarder: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) python-pillow: Pillow: Denial of Service via decompression bomb in FITS image processing (CVE-2026-40192) Bug Fix(es): orphan cleanup triggers CapsuleContent::UpdateContentCounts regardless of automatic_content_count_updates setting (SAT-47204) Solution Before applying this update, make sure all previously released errata relevant to your system have been applied. For detailed instructions how to apply this update, refer to: https://docs.redhat.com/en/documentation/red_hat_satellite/6.18/html/updating_red_hat_satellite/index Affected Products Red Hat Satellite 6.18 x86_64 Red Hat Satellite Capsule 6.18 x86_64 Red Hat Enterprise Linux for x86_64 9 x86_64 Fixes BZ - 2452230 - CVE-2026-5135 foreman: Foreman: Unauthorized modification of host configurations via broken access control BZ - 2452970 - CVE-2026-5136 foreman: Foreman: Privilege escalation to administrator-level access via usergroup role assignment manipulation BZ - 2452971 - CVE-2026-5138 foreman: Foreman: Information disclosure via improper validation of nested request parameters BZ - 2452999 - CVE-2026-5142 foreman: foreman: Cross-tenant private SSH key disclosure via taxonomy scoping bypass BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2458856 - CVE-2026-40192 Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing SAT-47204 - orphan cleanup triggers CapsuleContent::UpdateContentCounts regardless of automatic_content_count_updates setting [rhn_satellite_6.18] CVEs CVE-2026-5135 CVE-2026-5136 CVE-2026-5138 CVE-2026-5142 CVE-2026-32282 CVE-2026-40192 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Satellite 6.18 SRPM foreman-3.16.0.17-1.el9sat.src.rpm SHA-256: 22bbd1146259b0b85611c19fad7060495cce67609a3d60df0037534f43265f1d python3.12-pillow-12.2.0-1.el9pc.src.rpm SHA-256: 59d9f4885bdaf4edd4f766fa1bcfd1a317cc4c8441053e44a734916382d08f62 rubygem-katello-4.18.0.14-1.el9sat.src.rpm SHA-256: 4dcce1d5076b6ad3f160ec703a0d53d99a90ac3aa622598d13a3a9d9f8b8c2b0 satellite-6.18.7-1.el9sat.src.rpm SHA-256: b6f1f3add0ab6cd03d0ef07e8c8a3cf9442e7165f078628e656950f8534e7ea5 yggdrasil-worker-forwarder-0.0.3-5.el9sat.src.rpm SHA-256: c5acc8c634c5e0716829c648395035fb570d835225d53f738d4193a63a8d8dd5 x86_64 foreman-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 2c86c4ebd35c246c727d0cc29fa5cdc5c1fe59d4b1b2488d431d0cd6a4a0e305 foreman-cli-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 5f83f7e83ff117199a0d8796335e804452a718341679fc020cb6e8e10f8d86b7 foreman-debug-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 03a69bc455a70be376624aa83201a1320e0c238c09e85843ae6002c79c96eebc foreman-dynflow-sidekiq-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 85174bfe893d16489f67bc95ba29f288af2f9a765898e8f887c7eddfd8bd559e foreman-ec2-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 5bd624e54a27409bc1466419dfedc2ed99d1d4c993b24b47ba9cb93739119b9e foreman-journald-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 4afefdbddf3b60f79499057af4b20ea2b5a16c3fff5e170c0a0c841a37281244 foreman-libvirt-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 554465d641acdd26a69899f03f4d186835e102c42d06690449f26889fac128a6 foreman-openstack-3.16.0.17-1.el9sat.noarch.rpm SHA-256: f297f7e78b2b6e7acd3299ab5cf0cbce8ec5418116158d44f18277e4d4fd6817 foreman-pcp-3.16.0.17-1.el9sat.noarch.rpm SHA-256: d709fa9bf3a31acba056f5d9406fea2e21ca97048e9421437bfa90fa8649d035 foreman-postgresql-3.16.0.17-1.el9sat.noarch.rpm SHA-256: b6e38b42aded0b87935634fda173c2d31dc9e87b7c163a31b7e96b21215dbf96 foreman-redis-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 1a2cd28eb271b6d8646b1e5f3f9001a0fadacb8d07577d7b7d9f273f8556ae50 foreman-service-3.16.0.17-1.el9sat.noarch.rpm SHA-256: bb24daa9fc2c5216f8a5f958776d3098cf15cfcc818e72838dea0fe01ba12d53 foreman-telemetry-3.16.0.17-1.el9sat.noarch.rpm SHA-256: ae3749cdc45d3254148b617b9847169a0badc53cf71c86ea19edf68154b190bc foreman-vmware-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 4f78de9e2455df459fcc18328d95a2eb6f1114d1b5b8765976bd62f86b87871b python3.12-pillow-12.2.0-1.el9pc.x86_64.rpm SHA-256: 3099a2788707a166f372383a874c6bb4e295202aff9c1c8327ecdaf50f767548 python3.12-pillow-debuginfo-12.2.0-1.el9pc.x86_64.rpm SHA-256: f558680035155edda2e9fd84ed6de4d23a8b6be72df5c6cf94d1b085df081206 python3.12-pillow-debugsource-12.2.0-1.el9pc.x86_64.rpm SHA-256: 391a76eebe6e287c196808b3a9c765696597dcffb8774662e65d190d67a84732 rubygem-katello-4.18.0.14-1.el9sat.noarch.rpm SHA-256: fe35d0e1807ee71a8f2e3fe3dadb995ae67ed826d47eda40d91b3bc8b585e146 satellite-6.18.7-1.el9sat.noarch.rpm SHA-256: 7b8b6c8dd7e4e80e8468324c435d7ed119dc480d5c712c7e534b6bf1317284dc satellite-cli-6.18.7-1.el9sat.noarch.rpm SHA-256: 2ecbed79b13fa1ef5ff65f5731e30951c08bb4bc9740834003cdcf2cfc8d74e6 satellite-common-6.18.7-1.el9sat.noarch.rpm SHA-256: fddaabece71cb258ba378004bef34396795c5ed2172612408dd177c1457bbf55 satellite-obsolete-packages-6.18.7-1.el9sat.noarch.rpm SHA-256: d88df7f7235fc1b599b494283b504fbafbfb9bce52c5bf756367edcf4f38dfe5 yggdrasil-worker-forwarder-0.0.3-5.el9sat.x86_64.rpm SHA-256: b60c37bfd0f45f36d8c673c4bb71f919a874cb8e66e463e7add4ce55d1a80226 Red Hat Satellite Capsule 6.18 SRPM foreman-3.16.0.17-1.el9sat.src.rpm SHA-256: 22bbd1146259b0b85611c19fad7060495cce67609a3d60df0037534f43265f1d python3.12-pillow-12.2.0-1.el9pc.src.rpm SHA-256: 59d9f4885bdaf4edd4f766fa1bcfd1a317cc4c8441053e44a734916382d08f62 satellite-6.18.7-1.el9sat.src.rpm SHA-256: b6f1f3add0ab6cd03d0ef07e8c8a3cf9442e7165f078628e656950f8534e7ea5 x86_64 foreman-debug-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 03a69bc455a70be376624aa83201a1320e0c238c09e85843ae6002c79c96eebc foreman-pcp-3.16.0.17-1.el9sat.noarch.rpm SHA-256: d709fa9bf3a31acba056f5d9406fea2e21ca97048e9421437bfa90fa8649d035 python3.12-pillow-12.2.0-1.el9pc.x86_64.rpm SHA-256: 3099a2788707a166f372383a874c6bb4e295202aff9c1c8327ecdaf50f767548 python3.12-pillow-debuginfo-12.2.0-1.el9pc.x86_64.rpm SHA-256: f558680035155edda2e9fd84ed6de4d23a8b6be72df5c6cf94d1b085df081206 python3.12-pillow-debugsource-12.2.0-1.el9pc.x86_64.rpm SHA-256: 391a76eebe6e287c196808b3a9c765696597dcffb8774662e65d190d67a84732 satellite-capsule-6.18.7-1.el9sat.noarch.rpm SHA-256: 59899948a428c88a28d8734e9b8c8beb4fc05461fd14da25f4f322e8eb0b01d6 satellite-common-6.18.7-1.el9sat.noarch.rpm SHA-256: fddaabece71cb258ba378004bef34396795c5ed2172612408dd177c1457bbf55 satellite-obsolete-packages-6.18.7-1.el9sat.noarch.rpm SHA-256: d88df7f7235fc1b599b494283b504fbafbfb9bce52c5bf756367edcf4f38dfe5 Red Hat Enterprise Linux for x86_64 9 SRPM foreman-3.16.0.17-1.el9sat.src.rpm SHA-256: 22bbd1146259b0b85611c19fad7060495cce67609a3d60df0037534f43265f1d satellite-6.18.7-1.el9sat.src.rpm SHA-256: b6f1f3add0ab6cd03d0ef07e8c8a3cf9442e7165f078628e656950f8534e7ea5 x86_64 foreman-cli-3.16.0.17-1.el9sat.noarch.rpm SHA-256: 5f83f7e83ff117199a0d8796335e804452a718341679fc020cb6e8e10f8d86b7 satellite-cli-6.18.7-1.el9sat.noarch.rpm SHA-256: 2ecbed79b13fa1ef5ff65f5731e30951c08bb4bc9740834003cdcf2cfc8d74e6 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
This important update for Red Hat Satellite 6.18 addresses multiple vulnerabilities, including broken access control allowing unauthorized host configuration modification (CVE-2026-5135, CVSS 6.5), privilege escalation via usergroup manipulation (CVE-2026-5136, CVSS 8.8), and cross-tenant SSH key disclosure via a scoping bypass. The patch fixes these flaws in Satellite and Capsule version 6.18, requiring an update to Satellite 6.18.7. Administrators should apply this update after ensuring all previous errata are installed.