SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79654

MEDIUM · CVSS 4.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A vulnerability exists in the Content View History API of Katello, allowing authenticated users to bypass authorization and access lifecycle history data of Content Views from other organizations by manipulating the API endpoint. This can lead to unauthorized disclosure of sensitive information, such as publication events and associated user details. Organizations using Katello should prioritize addressing this issue to prevent potential data leaks between different organizational units.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79654
Severity
MEDIUM
CVSS
4.3
EPSS
0.33%

Original NVD Description

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization by supplying its identifier to the affected API endpoint. This can result in unauthorized disclosure of Content View lifecycle information, including publication and promotion events, associated users, and timestamps.