PatchSiren cyber security CVE debrief
CVE-2026-106471 Red Hat CVE debrief
A flaw in Candlepin's central authorization filter allows unauthorized access to consumer information and modification of entitlements when a low-privilege authenticated attacker can access the first referenced object and knows target resource identifiers. This vulnerability, present in Candlepin within Red Hat Satellite 6 deployments, enables bypassing of authorization checks on subsequent objects, potentially leading to unauthorized disclosure of consumer information and modification of entitlements and related subscription resources.
- Vendor
- Red Hat
- Product
- Red Hat Satellite 6
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Red Hat Satellite 6 deployments using Candlepin should assess exposure and prioritize patching and monitoring to prevent unauthorized access to consumer information and modification of entitlements.
Why it matters
Defenders should prioritize verifying and patching Candlepin instances in Red Hat Satellite 6 deployments to prevent unauthorized access to consumer information and modification of entitlements. Monitoring for suspicious access patterns is also recommended. The vulnerability allows a low-privilege authenticated attacker to bypass authorization checks when target resource identifiers are known.
- Potential unauthorized disclosure of consumer information
- Potential unauthorized modification of entitlements and related subscription resources
- Bypassing of authorization checks on subsequent objects
- Verification of user permissions and access controls required
Technical summary
The Candlepin central authorization filter incorrectly grants access when any one of multiple @Verify-annotated parameters is accessible, instead of requiring access to every verified entity. This allows a low-privilege authenticated attacker to bypass authorization checks on subsequent objects when target resource identifiers are known, potentially leading to unauthorized disclosure of consumer information and modification of entitlements and related subscription resources in Red Hat Satellite 6 deployments using Candlepin.
Defensive priority
Defenders should prioritize verifying and patching Candlepin instances, especially in Red Hat Satellite 6 deployments, and monitor for suspicious access patterns.
Recommended defensive actions
- Verify and apply patches for Candlepin in Red Hat Satellite 6 deployments
- Monitor Candlepin instances for suspicious access patterns
- Restrict access to sensitive resources and verify user permissions
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information on the vulnerability. Red Hat has also provided a reference for the vulnerability. The vulnerability has been confirmed in Candlepin within Red Hat Satellite 6 deployments. Defenders should verify the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106471 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106471
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106471 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106471
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Candlepin: candlepin: broken object-level authorization via verifyauthorizationfilter multi-@ver
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/106xxx/CVE-2026-106471.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-106471
Supplemental source - vdb-entry, x_refsource_REDHAT
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.