RHSA-2026:28438HighCVSS 7.8

Red Hat Security Advisory: satellite/foreman-mcp-server-rhel9 container image available as a Technology Preview

Published
June 23, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-9073 — foreman-mcp-server: MCP Server: Insecure Sensitive HTTP Header Sanitization CVE-2026-12112 — foreman-mcp-server: MCP Server: Active Session Hijacking via Insecure Session State Reuse

🎯 Affected products2

  • Red Hat Satellite 6.19
  • registry.redhat.io/satellite/foreman-mcp-server-rhel9@sha256:0130440128fabdff55b67256d444d2edca40912b65e65b8569964738f85d3069_amd64 as a component of Red Hat Satellite 6.19

✅ Remediation

For Satellite MCP integration see the Red Hat Satellite documentation. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

🔗 References (7)