CVE-2026-0980
8.3Red Hat · Satellite
A command injection vulnerability in the rubyipmi gem within Red Hat Satellite allows authenticated users to achieve remote code execution via a maliciously crafted BMC username.
Executive summary
Red Hat Satellite is vulnerable to remote code execution due to an OS command injection flaw in the rubyipmi component, requiring immediate remediation.
Vulnerability
This is an OS command injection vulnerability (CWE-78) occurring within the Baseboard Management Controller component. An attacker with authenticated access and host creation or update permissions can trigger the flaw by supplying a malicious username, leading to arbitrary command execution on the underlying system.
Business impact
The ability for an authenticated user to execute arbitrary commands on the Red Hat Satellite server poses a severe risk to the entire managed infrastructure. Given the CVSS score of 8.3, this high-severity vulnerability could lead to a total compromise of the management platform, allowing attackers to pivot into connected systems, exfiltrate sensitive configuration data, or disrupt enterprise-wide software deployment pipelines.
Remediation
Immediate Action: Apply the vendor-provided security updates identified in the Red Hat errata (RHSA-2026:5968, RHSA-2026:5970, and RHSA-2026:5971) to ensure the rubyipmi gem is updated to the fixed versions.
Proactive Monitoring: Audit access logs for suspicious user account modifications or unusual activity originating from accounts with host management privileges.
Compensating Controls: Restrict administrative access to the Satellite management interface to only essential personnel, and ensure the environment is protected by network segmentation to prevent unauthorized access to the BMC management plane.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the potential for full system compromise, organizations should prioritize the deployment of the official Red Hat security patches. Ensure that internal procedures for updating Red Hat Satellite are followed immediately to mitigate the risk of command injection, as authenticated attackers could leverage this flaw to gain persistent control over the Satellite management infrastructure.
More Red Hat CVEs
Sources
- RHSA-2026:5968 Vendor advisory
- RHSA-2026:5970 Vendor advisory
- RHSA-2026:5971 Vendor advisory
- Vulnerability database entry
- RHBZ#2429874 Issue tracker