PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107444 Red Hat CVE debrief

CVE-2026-107444 debrief: A flaw in Katello's Docker Tags repositories API allows unauthorized disclosure of repository configuration information across organization boundaries. An authenticated user with permission to view products in one organization may retrieve repository metadata associated with Docker tags belonging to another organization. This vulnerability impacts organizations using Red Hat Satellite 6 and Red Hat Hardened Images. Defenders managing these systems should assess their exposure, verify configurations, and review logs for potential unauthorized access.

Vendor
Red Hat
Product
Red Hat Hardened Images
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders managing Red Hat Satellite 6 and Red Hat Hardened Images should assess their exposure to this vulnerability. They should verify their current configurations and review logs for potential unauthorized access.

Why it matters

CVE-2026-107444 allows unauthorized disclosure of repository configuration information across organization boundaries in Katello's Docker Tags repositories API. Defenders managing Red Hat Satellite 6 and Red Hat Hardened Images should assess exposure, verify configurations, review logs, and prioritize updates.

  • Potential unauthorized disclosure of repository configuration information
  • Possible retrieval of repository metadata across organization boundaries
  • Need for verification of exposure in environments using affected systems
  • Priority on updating affected systems as patches become available

Technical summary

The Docker Tags repositories API in Katello does not properly enforce organization scoping when listing repositories for a Docker meta tag. This allows an authenticated user with permission to view products in one organization to retrieve repository metadata associated with Docker tags belonging to another organization. The vulnerability impacts organizations using Red Hat Satellite 6 and Red Hat Hardened Images. Defenders should prioritize verifying exposure in their environments, especially those using affected systems.

Defensive priority

Defenders should prioritize verifying exposure in their environments, especially those using Red Hat Satellite 6 and Red Hat Hardened Images. They should assess their current configurations, review logs for potential unauthorized access, and update affected systems as patches become available.

Recommended defensive actions

  • Verify exposure in environments using Red Hat Satellite 6 and Red Hat Hardened Images
  • Review logs for potential unauthorized access
  • Update affected systems as patches become available
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability in Katello's Docker Tags repositories API. The NVD entry is currently UNCLASSIFIED. Evidence is limited to the information provided in the CVE record and source item. Defenders should verify the current configurations and review logs for potential unauthorized access in environments using affected systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107444 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107444

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107444 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107444

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.