Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates when/if they become available.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Rubygem-katello: katello docker tags repositories api cross-organization authorization bypass | Rubygem-katello: katello: katello: katello docker tags repositories api cross-organization authorization bypass |
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 08 Oct 2026 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in Katello where the Docker Tags repositories API does not properly enforce organization scoping when listing repositories for a Docker meta tag. An authenticated user with permission to view products in one organization may be able to retrieve repository metadata associated with Docker tags belonging to another organization by supplying the tag identifier. This can result in unauthorized disclosure of repository configuration information across organization boundaries. | |
| Title | Rubygem-katello: katello docker tags repositories api cross-organization authorization bypass | |
| First Time appeared |
Redhat
Redhat hummingbird Redhat satellite |
|
| Weaknesses | CWE-639 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/a:redhat:satellite:6 |
|
| Vendors & Products |
Redhat
Redhat hummingbird Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-08T22:19:03.642Z
Reserved: 2026-10-08T03:29:12.521Z
Link: CVE-2026-107444
Updated: 2026-10-08T14:31:26.677Z
Status : Awaiting Analysis
Published: 2026-10-08T04:17:14.237
Modified: 2026-10-08T20:49:23.240
Link: CVE-2026-107444
OpenCVE Enrichment
Updated: 2026-10-08T06:30:17Z