CVE-2026-12541EPSS p69.6%
CVE-2026-12541CVE-2026-12541
Description
A flaw was found in Foreman. OS command injection vulnerabilities exist in the foreman-rake db:dump and db:import_dump tasks. The application fails to properly sanitize user-supplied input in the destination parameter (during backups) and the file parameter (during imports) before passing them to a Ruby system() call for execution. An attacker with permissions to execute foreman-rake (e.g., via a restricted sudo configuration) can append malicious shell commands to the provided file paths.
Scoring
| CVSS | 8.2 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 1.31% probability of exploitation · percentile 69.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-10-02 |