A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Katello where the Flatpak Remote Repositories API does not properly enforce authorization when accessing a flatpak remote repository by identifier. An authenticated user with permission to view flatpak remotes in one organization may be able to access flatpak remote repository information belonging to another organization. The same unscoped lookup is used by the mirror action, which may allow creating a repository in a product the user can edit that is configured with another organization's flatpak remote URL and stored remote credentials. | |
| Title | Rubygem-katello: katello flatpak remote repositories api cross-organization authorization bypass | |
| First Time appeared |
Redhat
Redhat hummingbird Redhat satellite |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat hummingbird Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T03:43:03.553Z
Reserved: 2026-10-08T03:29:15.423Z
Link: CVE-2026-107445
No data.
Status : Received
Published: 2026-10-08T04:17:19.220
Modified: 2026-10-08T04:17:19.220
Link: CVE-2026-107445
No data.
OpenCVE Enrichment
No data.
Weaknesses