Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-12112: Session hijacking flaw in foreman-mcp-server enables privilege escalation

A session management vulnerability in the foreman-mcp-server MCP Server lets unauthenticated attackers hijack active administrative sessions, because authenticated client connections are improperly cached, session IDs are trusted without re-validating authentication tokens, and newly created session IDs are written to standard logs. Exploitation can lead to privilege escalation and infrastructure-wide code execution.

Disclosed 23 June 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers could hijack administrative MCP sessions, resulting in privilege escalation and potential infrastructure-wide code execution. Red Hat published errata (RHSA-2026:28405, RHSA-2026:28438) addressing the issue.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-12112