CVE-2026-12515
katello: missing repository authorization in content_uploads exposes cross-product content existence
Description
A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.
How to fix CVE-2026-12515
To remediate CVE-2026-12515, upgrade the affected package to a fixed version below.
- —upgrade to 4.21.0.rc1 or later
Is CVE-2026-12515 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-12515.
Affected packages (1)
- from 0, < 4.21.0.rc1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |