Skip to content
VulniPulse
Medium4.3Red Hat Linux

Medium [CVE-2026-12515] Katello: missing repository authorization in content_uploads exposes cross-product content existence

This medium-severity Red Hat Linux advisory covers CVE-2026-12515 affecting Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9, Red Hat Satellite 6.17 for RHEL 9.

CVE-2026-12515 Published Jun 17, 2026Updated by vendor Aug 4, 2026
Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open vendor advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage.

An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.

Affected products named by the advisory: Red Hat Satellite 6.16 for RHEL 8; Red Hat Satellite 6.16 for RHEL 9; Red Hat Satellite 6.17 for RHEL 9; Red Hat Satellite 6.18 for RHEL 9; and 2 more.

Affected products named by the advisory: Red Hat Satellite 6.19 for RHEL 9.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source

Mitigation

The source record does not include mitigation steps. That is not a statement that no fix exists — read the vendor advisory below for the authoritative guidance.

Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.