CVE-2026-92894

A flaw was found in the foreman_ansible plugin's Ansible override values API. The destroy action resolves the target LookupValue record by ID without verifying it belongs to an AnsibleVariable the caller is authorized to edit. An authenticated user with the edit_ansible_variables permission can delete any LookupValue by ID, including override values for Ansible variables outside their permission filter scope and override values belonging to Puppet smart class parameters.
Configurations

No configuration.

History

17 Sep 2026, 10:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-17 10:17

Updated : 2026-09-17 15:17


NVD link : CVE-2026-92894

Mitre link : CVE-2026-92894

CVE.ORG link : CVE-2026-92894


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization