CVE-2026-12112: Session hijacking flaw in foreman-mcp-server enables privilege escalation
A session management vulnerability in the foreman-mcp-server MCP Server lets unauthenticated attackers hijack active administrative sessions, because authenticated client connections are improperly cached, session IDs are trusted without re-validating authentication tokens, and newly created session IDs are written to standard logs. Exploitation can lead to privilege escalation and infrastructure-wide code execution.
Disclosed 23 June 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers could hijack administrative MCP sessions, resulting in privilege escalation and potential infrastructure-wide code execution. Red Hat published errata (RHSA-2026:28405, RHSA-2026:28438) addressing the issue.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-12112
