{
  "threat_severity" : "Moderate",
  "public_date" : "2026-06-17T15:27:46Z",
  "bugzilla" : {
    "description" : "katello: missing repository authorization in content_uploads exposes cross-product content existence",
    "id" : "2489812",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2489812"
  },
  "cvss3" : {
    "cvss3_base_score" : "4.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-862",
  "details" : [ "A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content.", "A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization checks in the ContentUploadsController allowed users with the edit_products permission to query content information for repositories outside the products they were authorized to manage. An authenticated attacker could exploit this issue to determine whether specific content exists within repositories that should otherwise be inaccessible. This issue does not allow unauthorized modification, import, or publication of content." ],
  "statement" : "This vulnerability affects Katello's content upload API authorization handling. Red Hat Product Security has assessed this issue as a Moderate severity vulnerability.\nKatello's content_uploads API does not properly enforce repository authorization checks when processing upload requests. A user with product-filtered edit_products permissions may query repositories outside their authorized scope and determine whether matching content exists within the Pulp content store.\nThe issue arises because the API allows operations against repositories that are not covered by the caller's product-scoped permissions. The response behavior may disclose whether matching content already exists, potentially revealing information about content associated with repositories that would otherwise be inaccessible to the user.\nBecause the impact is limited to disclosure of repository information, Red Hat assessed the Confidentiality impact as Low (C:L), with no demonstrated Integrity or Availability impact.",
  "affected_release" : [ {
    "product_name" : "Red Hat Satellite 6.16 for RHEL 8",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:50223",
    "cpe" : "cpe:/a:redhat:satellite:6.16::el8",
    "package" : "rubygem-katello-0:4.14.0.21-1.el8sat"
  }, {
    "product_name" : "Red Hat Satellite 6.16 for RHEL 9",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:50223",
    "cpe" : "cpe:/a:redhat:satellite:6.16::el9",
    "package" : "rubygem-katello-0:4.14.0.21-1.el9sat"
  }, {
    "product_name" : "Red Hat Satellite 6.17 for RHEL 9",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:50222",
    "cpe" : "cpe:/a:redhat:satellite:6.17::el9",
    "package" : "rubygem-katello-0:4.16.0.18-1.el9sat"
  }, {
    "product_name" : "Red Hat Satellite 6.18 for RHEL 9",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:50263",
    "cpe" : "cpe:/a:redhat:satellite:6.18::el9",
    "package" : "rubygem-katello-0:4.18.0.15-1.el9sat"
  }, {
    "product_name" : "Red Hat Satellite 6.19 for RHEL 9",
    "release_date" : "2026-08-04T00:00:00Z",
    "advisory" : "RHSA-2026:50221",
    "cpe" : "cpe:/a:redhat:satellite:6.19::el9",
    "package" : "rubygem-katello-0:4.20.0.7-1.el9sat"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Hardened Images",
    "fix_state" : "Not affected",
    "package_name" : "ctags",
    "cpe" : "cpe:/a:redhat:hummingbird:1"
  }, {
    "product_name" : "Red Hat Satellite 6",
    "fix_state" : "Affected",
    "package_name" : "satellite:el8/rubygem-katello",
    "cpe" : "cpe:/a:redhat:satellite:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-12515\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-12515\nhttps://github.com/Katello/katello/pull/11712" ],
  "name" : "CVE-2026-12515",
  "mitigation" : {
    "value" : "Red Hat is not aware of a practical temporary workaround that fully mitigates this issue or meets Red Hat Product Security's standards for usability, deployment, applicability, or stability. Customers are advised to apply the relevant security updates if they become available.",
    "lang" : "en:us"
  },
  "csaw" : false
}