Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-92904

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Sep 17, 2026
Vendor unknown

Description

A flaw was found in the foreman_remote_execution plugin's template invocations controller. The show_template_invocation_by_host action resolves the job invocation by ID without evaluating the caller's view_job_invocations permission filter against the record. An authenticated user whose job invocation visibility is restricted by a permission filter can enumerate job invocation IDs and read the live output, rendered script, and input values for other users' job invocations within their own organizations.

References