← Vulnerability feed

Vulnerability record · CVE-2018-14643 · published 21 September 2018

CVE-2018-14643: Theforeman foreman improper authentication vulnerability

Theforeman · Foreman

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

9.8 CVSS 3.0 Critical EPSS 6.1% · top 6.9% CWE-592 · CWE-592CWE-287 · Improper authentication
9.8CVSS 3.0 base score, v2 10.0
6.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-14643 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2022-3874Redhat satellite os command injection vulnerabilityA command injection flaw was found in foreman. This flaw allows an authenticated user with admin privileges on the foreman instance to transpile comm…EPSS 2.2%9.1CVE-2023-0118Theforeman foreman os command injection vulnerabilityAn arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates and execute arbitrary code on …EPSS 1.4%9.1CVE-2023-0462Theforeman foreman code injection vulnerabilityAn arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating syste…EPSS 0.96%8.8CVE-2026-5136Redhat satellite vulnerabilityA flaw was found in Foreman. The Usergroup model in Foreman does not properly validate role assignments against the calling user's permissions. This …EPSS 0.56%8.8CVE-2021-3590Theforeman foreman information exposure vulnerabilityA flaw was found in Foreman project. A credential leak was identified which will expose Azure Compute Profile password through JSON of the API output…EPSS 0.67%8.8CVE-2017-2672Theforeman foreman cleartext storage of sensitive data vulnerabilityA flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file woul…EPSS 1.2%8.8CVE-2016-9593Theforeman foreman insufficiently protected credentials vulnerabilityforeman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able…EPSS 0.97%8.8CVE-2018-1097Theforeman foreman information exposure vulnerabilityA flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the us…EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2018-14643), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.