Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials. | |
| Title | Rubygem-katello: katello flatpak remote repositories api cross-organization authorization bypass | |
| First Time appeared |
Redhat
Redhat hummingbird Redhat satellite |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat hummingbird Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T03:43:03.553Z
Reserved: 2026-10-08T03:29:15.423Z
Link: CVE-2026-107445
No data.
Status : Received
Published: 2026-10-08T04:17:19.220
Modified: 2026-10-08T04:17:19.220
Link: CVE-2026-107445
No data.
OpenCVE Enrichment
Updated: 2026-10-08T06:00:10Z
-
CWE-639
Authorization Bypass Through User-Controlled Key