PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-103870 Red Hat CVE debrief

A flaw in pulp-rpm allows a user who can sync or upload a distribution tree to create a new directory outside the task work area and write repository metadata and packages there, as the Pulp worker user. An existing file or directory is not replaced. The flaw does not disclose data and does not stop the service. This issue affects Red Hat Satellite 6 and Red Hat Update Infrastructure systems, which may be exposed if not properly patched or mitigated. Defenders should assess their exposure and prioritize patching or mitigation.

Vendor
Red Hat
Product
Red Hat Satellite 6
CVSS
MEDIUM 5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Red Hat Satellite 6 and Red Hat Update Infrastructure systems should assess exposure and prioritize patching or mitigation. This includes reviewing synchronization and upload processes, monitoring for suspicious activity, and applying patches or mitigations provided by Red Hat. Additionally, security teams and vulnerability management teams should be aware of the potential impact of this flaw on their systems and take steps to rem

Why it matters

Defenders should prioritize verifying affected systems, reviewing synchronization and upload processes, and applying patches or mitigations provided by Red Hat to prevent exploitation of the pulp-rpm flaw.

  • Verify affected systems and apply patches or mitigations provided by Red Hat to prevent directory creation outside task work areas.
  • Review synchronization and upload processes to prevent exploitation by users with sync or upload privileges.
  • Monitor for suspicious activity related to pulp-rpm, such as unexpected directory creation or changes to repository metadata.

Technical summary

A flaw in pulp-rpm allows a user who can sync or upload a distribution tree to create a new directory outside the task work area and write repository metadata and packages there, as the Pulp worker user. This issue is caused by the use of addon and variant ids from .treeinfo as directory names, which can lead to directory traversal and unauthorized data writes. The flaw does not disclose data and does not stop the service, but it may allow an attacker to write data outside the intended repository structure. Defenders should prioritize verifying affected systems, reviewing synchronization and upload processes, and applying patches or mitigations provided by Red Hat.

Defensive priority

Defenders should prioritize verifying affected systems, reviewing synchronization and upload processes, and applying patches or mitigations provided by Red Hat.

Recommended defensive actions

  • Verify affected Red Hat Satellite 6 and Red Hat Update Infrastructure systems and apply patches or mitigations provided by Red Hat
  • Review synchronization and upload processes to prevent exploitation by users with sync or upload privileges
  • Monitor for suspicious activity related to pulp-rpm, such as unexpected directory creation or changes to repository metadata
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details on the flaw in pulp-rpm. Red Hat has provided references to affected products and patches. The flaw allows a user with sync or upload privileges to create directories outside the task work area, potentially leading to unauthorized data writes. Evidence is limited to CVE and NVD details, with Red Hat providing additional guidance on affected products and patches.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-103870 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-103870

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-103870 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-103870

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.