CVE-2026-12515: Katello Authorization Flaw Allows Repository Content Enumeration
CVE-2026-12515 is a security flaw in Katello, the content management component of Red Hat Satellite, that allows authenticated users with product-editing permissions to discover what content exists in repositories they shouldn't have access to. An attacker with edit_products permission could query the ContentUploadsController to learn whether specific files or packages exist in off-limits repositories—potentially valuable reconnaissance for follow-up attacks. The vulnerability does not enable attackers to actually modify, import, or publish content; it's strictly an information disclosure issue.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Weaknesses (CWE)
- CWE-862
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-26
NVD description (verbatim)
A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.
3 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from insufficient authorization checks in Katello's ContentUploadsController. Users granted the edit_products permission are intended to manage only their assigned products, but the content upload API does not properly validate that query requests are scoped to authorized repositories. An authenticated attacker can therefore craft requests to probe repository contents outside their permission boundary, leveraging missing authorization logic to enumerate what content is present. This is classified as an authorization/access control flaw (CWE-862) with low attack complexity—the exploitation requires only standard API calls and valid authentication credentials.
Business impact
For Red Hat Satellite deployments, this vulnerability enables internal reconnaissance and competitive intelligence gathering by privileged-but-restricted users. An employee or contractor with product-management rights could discover confidential content (package versions, security patches, proprietary software) in repositories they're not meant to see. While direct data exfiltration or modification isn't possible, the information disclosure can inform lateral movement, privilege escalation, or supply-chain attacks. Organizations using fine-grained repository access controls to segregate products or customers are most at risk, as the flaw undermines the assumed security boundaries.
Affected systems
Red Hat Satellite deployments running Katello are affected. This includes customers using Satellite for content management, patching, and lifecycle management across their infrastructure. The vulnerability applies to any Katello instance where users have been assigned edit_products permissions and repository access should be restricted by product assignment.
Exploitability
The vulnerability requires authentication and edit_products permission—a non-trivial barrier. However, the attack surface is wide: any user with product-editing rights (not uncommon in medium to large Satellite deployments) can execute the reconnaissance. The API call is straightforward with low complexity (no multi-step exploitation, no race conditions). An attacker must simply issue queries to the ContentUploadsController with repository identifiers they're testing. No CVSS score indicates this vulnerability is not on the CISA Known Exploited Vulnerabilities (KEV) catalog, suggesting limited public weaponization to date.
Remediation
Organizations should prioritize patching Katello to the version that corrects authorization checks in ContentUploadsController. Until patching is complete, restrict edit_products permission to only trusted users and implement auditing of content-upload API calls to detect suspicious enumeration patterns. Review Satellite RBAC configurations to ensure permissions align with actual job functions and limit the blast radius if an account is compromised.
Patch guidance
Consult the Red Hat Satellite security advisory for the fixed Katello version. Test patches in a staging environment before production deployment, particularly if your Satellite instance manages critical infrastructure content. Red Hat typically releases advisories with specific version numbers and may provide guidance on incremental vs. major updates. Verify the patch resolves authorization checks in the ContentUploadsController against your custom automation if you have integrated content-upload workflows.
Detection guidance
Monitor Satellite audit logs for repeated or suspicious queries to the ContentUploadsController API, especially from users querying repositories outside their assigned product scope. Look for patterns such as rapid enumeration of repository IDs, queries from unexpected source IPs, or off-hours API activity by edit_products users. Implement alerting on failed authorization attempts if Satellite logs them. Network-level detection is difficult since the flaw exploits legitimate API endpoints; focus on behavioral analysis and access log correlation.
Why prioritize this
Although the CVSS score is medium (4.3) and the vulnerability is information-disclosure only, prioritization depends on your deployment model and user base. If your Satellite instance serves segregated customers or products with strict access boundaries, the reconnaissance capability is operationally significant and warrants timely patching. If Satellite is used primarily in an internal, single-tenant environment with fewer trust boundaries, the risk is lower. The lack of KEV status suggests this is not yet a major attack vector in the wild.
Risk score, explained
The CVSS 3.1 score of 4.3 reflects low impact (information disclosure, confidentiality impact only), low attack complexity, and the requirement for prior authentication and edit_products permission. The score accurately penalizes the vulnerability for not enabling modification or availability impact, but it may underweight the strategic value of repository enumeration in multi-tenant or segregated-product deployments. Organizations with strict data compartmentalization should consider their business context when mapping this score to internal risk ratings.
Frequently asked questions
Can an attacker use this to modify or delete repository content?
No. CVE-2026-12515 enables read-only reconnaissance. An attacker can determine what content exists in off-limits repositories but cannot import, publish, modify, or delete anything. Other authorization flaws or privilege escalation would be needed for destructive actions.
Does this affect Red Hat Enterprise Linux (RHEL) directly?
Not directly. The flaw is in Katello, which is the content management system within Red Hat Satellite. RHEL systems themselves are not vulnerable, but organizations using Satellite to manage RHEL patches and content should update Satellite to prevent unauthorized enumeration of their content repositories.
What if we restrict edit_products permission to only a small group of admins?
That significantly reduces risk. Fewer users with edit_products permission means fewer potential attackers and smaller insider-threat surface. However, a malicious or compromised admin can still exploit the flaw, so patching remains important.
Is this in the CISA KEV catalog?
No. As of the vulnerability publication date, this vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog, suggesting limited public exploitation. However, the lack of KEV status does not mean the vulnerability is unimportant—it should still be patched within your normal maintenance windows.
This analysis is based on publicly available information as of the vulnerability publication date. Patch version numbers and specific advisory links should be verified directly with Red Hat's security advisories. Exploit code or weaponized proof-of-concept details are not provided. Organizations should test patches in non-production environments and conduct risk assessments aligned with their specific Satellite deployment architecture and user base before applying mitigations. Source: NVD (public-domain), retrieved 2026-07-27. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2022-42479MEDIUMMissing Authorization in TemplateHouse Soledad – MEDIUM Severity Access Control Bypass
- CVE-2022-45813MEDIUMBeRocket Advanced AJAX Product Filters Missing Authorization Flaw
- CVE-2023-25969MEDIUMMissing Authorization in ThemeHunk Contact Form Plugin
- CVE-2023-32959MEDIUMMetroStore Missing Authorization Vulnerability – Patch Guide
- CVE-2024-24709MEDIUMShareaholic Missing Authorization Vulnerability – Update Required
- CVE-2024-31435MEDIUMMissing Authorization in Inisev Social Media & Share Icons Plugin—Patch Guidance
- CVE-2024-33685MEDIUMMissing Authorization in Jegstudio Startupzy 1.1.1 – MEDIUM Severity Vulnerability
- CVE-2024-33909MEDIUMMissing Authorization in Avirtum iPages Flipbook – CVSS 5.3 Patch Guide