PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-79654 Red Hat CVE debrief

CVE-2026-79654 debrief based on the supplied source corpus. The vulnerability is a flaw in Katello's Content View History API that allows an authenticated user with permission to view Content Views in one organization to access the lifecycle history of a Content View belonging to another organization. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps. Defenders should assess exposure and verify authorization for API access, particularly for authenticated users with permission to view Content Views. The vulnerability requires verification of affected versions, exploitation, и

Vendor
Red Hat
Product
Red Hat Satellite 6
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-26
Original CVE updated
2026-09-23
Advisory published
2026-08-26
Advisory updated
2026-09-23

Who should care

Roles and deployment contexts that should assess exposure include administrators and users with access to Content Views in Katello, as well as security teams responsible for monitoring and controlling access to sensitive information.

Why it matters

CVE-2026-79654 is a medium-severity vulnerability in Katello's Content View History API that allows unauthorized access to Content View lifecycle information. Defenders should assess exposure and verify authorization for API access, particularly for authenticated users with permission to view Content Views. The vulnerability requires verification of affected versions, exploitation, and remediation from official sources.

  • Potential unauthorized disclosure of Content View lifecycle information
  • Possible access to sensitive information, including publication and promotion events, associated users, and timestamps

Technical summary

A flaw in Katello's Content View History API allows an authenticated user with permission to view Content Views in one organization to access the lifecycle history of a Content View belonging to another organization. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps. The vulnerability requires verification of affected versions, exploitation, and remediation from official sources. Defenders should assess exposure and verify authorization for API access.

Defensive priority

Assess exposure and verify authorization for Content View History API access.

Recommended defensive actions

  • Verify authorization for Content View History API access
  • Assess exposure for authenticated users with permission to view Content Views
  • Review and update access controls for Content View lifecycle information
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and NVD entry provide details on the authorization flaw in Katello's Content View History API. The flaw allows an authenticated user with permission to view Content Views in one organization to access the lifecycle history of a Content View belonging to another organization. Evidence is limited to public sources, and defenders should verify affected scope, severity, and vendor guidance. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-79654 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-79654

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-79654 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79654

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.