Back to overview

CVE-2026-9073

MEDIUM
6.2
CVSS 3.1
Description
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The other, when debug logging is enabled, incompletely sanitizes HTTP request headers, leading to the cleartext logging of sensitive information such as authorization tokens and API keys. This vulnerability can result in a confidentiality breach, as sensitive authentication data is persisted in plain text within container logs, increasing the risk if logs are forwarded to a centralized platform.

Metadata

CVE ID
CVE-2026-9073
State
PUBLISHED
Assigner
redhat
Reserved
2026-05-20 12:18 UTC
Published
2026-06-23 19:53 UTC
Last updated
2026-06-23 19:53 UTC
Primary CWE
CWE-532
Insertion of Sensitive Information into Log File
Vendor / Product
Red Hat / Red Hat Satellite 6
Sources
cve.org  ·  NVD

Severity & Metrics

6.2 MEDIUM CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products (1)
VendorProductPlatformVersions
Red Hat Red Hat Satellite 6
Weakness (CWE)
CWESourceDescription
CWE-532 cna Insertion of Sensitive Information into Log File
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.2 MEDIUM 3.1 cna CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Back to overview