PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107445 Red Hat CVE debrief

CVE-2026-107445 debrief based on CVE Program and NVD records. The CVE record was published on 2026-10-08T03:43:03.553Z and has not been modified since then. This medium-severity vulnerability in the Katello Flatpak Remote Repositories API could allow cross-organization authorization bypass, potentially impacting Red Hat Satellite 6 and Red Hat Hardened Images deployments. Administrators should assess exposure and prioritize remediation based on organizational risk. The vulnerability is caused by the API not properly enforcing authorization when accessing a flatpak remote repository by identifier.

Vendor
Red Hat
Product
Red Hat Hardened Images
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Red Hat Satellite 6 and Red Hat Hardened Images administrators and security teams should assess exposure and prioritize remediation based on organizational risk. These stakeholders need to verify inventory for affected components, review compensating controls, and monitor for potential unauthorized access. They should also track exceptions, retest remediated assets, and ensure evidence is documented before closing the item.

Why it matters

CVE-2026-107445 is a medium-severity vulnerability in the Katello Flatpak Remote Repositories API, potentially allowing cross-organization authorization bypass. Red Hat Satellite 6 and Red Hat Hardened Images deployments may be affected. Administrators should assess exposure, verify inventory, and prioritize remediation based on organizational risk.

  • Potential unauthorized access to flatpak remote repository information
  • Possible creation of repositories in products with stored remote credentials
  • Need for verification of affected versions and remediation
  • Potential impact on confidentiality and integrity of repository data

Technical summary

The Katello Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier, potentially allowing authenticated users to access repository information belonging to another organization. This vulnerability could lead to unauthorized access to flatpak remote repository information and possible creation of repositories in products with stored remote credentials. The technical impact is medium severity, with potential effects on confidentiality and integrity of repository data.

Defensive priority

Assess exposure of Red Hat Satellite 6 and Red Hat Hardened Images deployments, verify inventory for affected components, and prioritize remediation based on organizational risk.

Recommended defensive actions

  • Assess exposure of Red Hat Satellite 6 and Red Hat Hardened Images deployments
  • Verify inventory for affected components
  • Prioritize remediation based on organizational risk
  • Monitor for potential unauthorized access to flatpak remote repository information
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE Program record and NVD vulnerability detail provide information on the authorization bypass vulnerability in the Katello Flatpak Remote Repositories API. Evidence is limited to publicly available records, and defenders should verify affected scope and vendor guidance within these constraints. The CVE record and NVD detail do not provide additional information on exploitation or affected versions beyond what is publicly known.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107445 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107445

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107445 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107445

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.