# Red Hat fixes Satellite flaw exposing host root passwords

_Published Friday, October 2, 2026 at 10:19 PM EDT · Security · Latest · Tier 2 — Notable_

![Red Hat fixes Satellite flaw exposing host root passwords — Primary](https://cybersecuritynews.com/wp-content/uploads/2026/10/Critical-Red-Hat-Satellite-Vulnerability-Could-Enable-Root-Password-Theft-and-Code-Execution-Attacks-1.webp)

Red Hat released fixes for a Satellite vulnerability that could let an authenticated user with only Viewer permissions retrieve sensitive host information, including root passwords. Publicly disclosed on Oct. 1, CVE-2026-96659 affects authorization checks in Foreman template preview endpoints used in infrastructure provisioning and management.

Red Hat assigned the flaw an Important severity rating and a CVSS v3 score of 9.1. Arbitrary command execution as the Foreman service account is also possible when template Safemode protections are disabled or circumvented. Satellite 6.16.14 includes Foreman version 3.12.0.23-1 for RHEL 8 and RHEL 9, alongside a fix for a separate Safemode bypass vulnerability.

## Sources

- [cybersecuritynews.com](https://cybersecuritynews.com/red-hat-satellite-vulnerability/)

---
Canonical: https://techandbusiness.org/newswire/0-Q5D5pyVqO1h4FItwI7jK
Published: 2026-10-03T02:19:15.625Z
Story chronology: 2026-10-01T00:00:00.000Z
Retrieved: 2026-10-03T04:40:15.560Z
Publisher: Tech & Business (techandbusiness.org)
