n
authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permissions. Unlike the REST API, which correctly enforces access controls, the GraphQL endpoint does not apply proper filtering, leading to an authorization bypass.
References
Configurations
No configuration.
History
27 Feb 2026, 08:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-27 08:17
Updated : 2026-02-27 14:06
NVD link : CVE-2025-9572
Mitre link : CVE-2025-9572
CVE.ORG link : CVE-2025-9572
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor