n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2025:21886 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2025:21893 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2025:21894 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2025:21897 | Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2025-9572 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2391715 | Issue Tracking |
| https://theforeman.org/security.html#2025-9572 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2026-02-27 08:17
Updated : 2026-03-24 12:16
NVD link : CVE-2025-9572
Mitre link : CVE-2025-9572
CVE.ORG link : CVE-2025-9572
JSON object : View
Products Affected
redhat
- satellite
- satellite_capsule
- enterprise_linux
theforeman
- foreman
CWE
CWE-863
Incorrect Authorization
