PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106471 Red Hat CVE debrief

A flaw in Candlepin's central authorization filter allows unauthorized access to consumer information and modification of entitlements when a low-privilege authenticated attacker can access the first referenced object and knows target resource identifiers. This vulnerability, present in Candlepin within Red Hat Satellite 6 deployments, enables bypassing of authorization checks on subsequent objects, potentially leading to unauthorized disclosure of consumer information and modification of entitlements and related subscription resources.

Vendor
Red Hat
Product
Red Hat Satellite 6
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Red Hat Satellite 6 deployments using Candlepin should assess exposure and prioritize patching and monitoring to prevent unauthorized access to consumer information and modification of entitlements.

Why it matters

Defenders should prioritize verifying and patching Candlepin instances in Red Hat Satellite 6 deployments to prevent unauthorized access to consumer information and modification of entitlements. Monitoring for suspicious access patterns is also recommended. The vulnerability allows a low-privilege authenticated attacker to bypass authorization checks when target resource identifiers are known.

  • Potential unauthorized disclosure of consumer information
  • Potential unauthorized modification of entitlements and related subscription resources
  • Bypassing of authorization checks on subsequent objects
  • Verification of user permissions and access controls required

Technical summary

The Candlepin central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. This allows a low-privilege authenticated attacker to bypass authorization checks on subsequent objects when target resource identifiers are known, potentially leading to unauthorized disclosure of consumer information and modification of entitlements and related subscription resources in Red Hat Satellite 6 deployments using Candlepin.

Defensive priority

Defenders should prioritize verifying and patching Candlepin instances, especially in Red Hat Satellite 6 deployments, and monitor for suspicious access patterns.

Recommended defensive actions

  • Verify and apply patches for Candlepin in Red Hat Satellite 6 deployments
  • Monitor Candlepin instances for suspicious access patterns
  • Restrict access to sensitive resources and verify user permissions
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. Red Hat has also provided a reference for the vulnerability. The vulnerability has been confirmed in Candlepin within Red Hat Satellite 6 deployments. Defenders should verify the official advisory and CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106471 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106471

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106471 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106471

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.