← back
CVE-2025-9572mediumCWE-863

Foreman: satellite: graphql api permission bypass leads to information disclosure

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5epss 0.3%
exploitation probability
0.3%top 72% of all CVEs
observed exploitation
nono source reports it
n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N