Hi, A security fix has been released in Foreman, an open-source lifecycle management tool for physical and virtual servers.
CVE-2026-96658: Foreman: Safemode bypass leading to RCE A low-privilege user permitted to render supplied template content can bypass Foreman's Safemode restrictions and reach Ruby code execution with Foreman service privileges. Affected versions: Foreman releases bundling Safemode before 2.0.1, including Foreman 3.19.0, 3.19.1, and 5.0.0 CVSS: 9.9 (Critical) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Fixed versions: Foreman 3.19.2 and 5.0.1; Safemode 2.0.1 or later must be installed Credit: Robb Gatica References: - Foreman Security: https://theforeman.org/security.html#2026-96658 - Redmine: https://projects.theforeman.org/issues/39845 - Fix: https://github.com/theforeman/safemode/pull/68 - Dependency update: https://github.com/theforeman/safemode/pull/69 Thanks, Ondrej Gajdusek Foreman Release Team
