Sceawere
Vulnerability Detail
CVE-2026-56097UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in Katello Registry
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.5
- Creation Date
- 1d ago
- Vendor
- Red Hat
- Product
- Red Hat Satellite 6.16 for RHEL 8
- Attack Type
- Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in rubygem-katello. An SQL injection vulnerability exists in the Red Hat Satellite Katello Registry Proxy. The application fails to sanitize input parameters used in database queries within the RegistryProxiesController. The methods check_blob_push_org_label and get_matching_products_from_org take user-supplied labels directly from the request path and interpolate them into raw SQL fragments. This flaw is accessible to a user with only the create_personal_access_tokens permission, even if the user access is restricted, with no Organization or Location assigned.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.5",
"pubDate": "2026-10-01T18:17:19.597Z",
"pubdate": "2026-10-01T18:17:19.597Z",
"executiveSummary": "A critical SQL injection vulnerability has been identified within the rubygem-katello component of Red Hat Satellite. The vulnerability resides in the RegistryProxy functionality, specifically within the RegistryProxiesController.\nThe flaw stems from the insecure handling of user-supplied input parameters, which are interpolated directly into raw SQL query fragments without adequate sanitization or parameterized querying.\nThe impact is significant, as it allows an authenticated attacker to manipulate database queries, potentially leading to unauthorized data exfiltration, modification, or deletion within the underlying database.\nExploitation is feasible by a user possessing minimal privileges, specifically those with 'create_personal_access_tokens' permissions. Notably, this risk persists even if the user account is restricted or lacks specific Organization or Location assignments, broadening the potential attack surface.\nSuccessful exploitation compromises the confidentiality and integrity of the Satellite instance. Organizations are advised to treat this as a high-priority security issue, as it bypasses standard authorization checks by exploiting the interface between the application layer and the database layer.",
"technicalDetails": "The vulnerability is classified as an SQL injection flaw localized within the RegistryProxiesController of the rubygem-katello component. The root cause is the failure to utilize secure abstraction layers—such as ActiveRecord's parameterized queries—when processing user-provided labels passed via the request path.\nSpecifically, the methods check_blob_push_org_label and get_matching_products_from_org act as the primary attack vectors. These methods extract labels directly from the URI path and inject them into raw SQL strings. Because the application fails to perform input validation or sanitization, an attacker can append malicious SQL syntax to the input string to alter the intended logic of the database query.\nThe attack flow proceeds as follows: 1) An attacker authenticates to the Red Hat Satellite environment using credentials that include the 'create_personal_access_tokens' permission. 2) The attacker crafts a request to the RegistryProxy endpoint where the URL path is manipulated to include SQL injection payloads in place of the expected 'org_label' parameter. 3) The RegistryProxiesController receives the malicious path, extracts the payload, and passes it unsanitized into the database interaction methods. 4) The backend database engine executes the injected SQL commands alongside the legitimate query. 5) By leveraging union-based, error-based, or boolean-based blind SQL injection techniques, the attacker can extract data from arbitrary tables within the database schema.\nThis vulnerability is particularly dangerous because it does not require administrative privileges. A user with the 'create_personal_access_tokens' role, even without assigned Organizations or Locations, has sufficient access to invoke the vulnerable controller methods. This effectively bypasses the application's intended role-based access control (RBAC) mechanisms, as the database layer processes the request before the application layer fully validates the user's scope.\nPost-exploitation impact includes the ability to bypass authentication, dump sensitive metadata, extract system configurations, or in some configurations, execute administrative SQL commands depending on the database user's privileges. The lack of sanitization creates a direct path from an authenticated user's request to the database execution context, representing a severe failure in input validation practices."
}