CVE detail
CVE-2026-5136
A flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This allows an authenticated user with usergroup management permissions to attach arbitrary roles, including administrative roles, to a user group and then add themselves as a member. Successful exploitation of this vulnerability leads to full privilege escalation, granting the attacker administrator-level access.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 10.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 6
- within the 30d window
- Peak daily
- 6
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://bugzilla.redhat.com/show_bug.cgi?id=2452970bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJul 1, 2026, 2:16 PM - https://access.redhat.com/security/cve/CVE-2026-5136access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 1, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:34368access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 1, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:34367access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 1, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:34366access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 1, 2026, 2:16 PM - https://access.redhat.com/errata/RHSA-2026:34365access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJul 1, 2026, 2:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-5142CVSS 6.5 · Medium
A flaw was found in foreman. Authenticated users with 'view_keypairs' permission can bypass taxonomy scoping, allowing them to download private SSH (Secure Shell) keys from other…
- CVE-2026-5138CVSS 4.3 · Medium
A flaw was found in Foreman. An authenticated user with host-edit permissions could exploit a cross-tenant information disclosure vulnerability. This flaw occurs because the taxon…
- CVE-2026-5135CVSS 6.5 · Medium
A flaw was found in Foreman. This broken access control vulnerability allows an authenticated user with host-edit permissions to retarget an existing lookup value override to a di…
- CVE-2025-9572CVSS 5.0 · Medium
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces acces…
- CVE-2023-0118CVSS 9.1 · Critical
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on the underlying operating syste…
- CVE-2021-20208CVSS 6.1 · Medium
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest…