THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-79654 (MEDIUM 4.3) — A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history

[NVD] CVE-2026-79654 (MEDIUM 4.3) — A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history

mednvdPublished 2026-08-26

CVE-2026-79654 CVSS: 4.3 MEDIUM Published: 2026-08-26T06:16:30.110

A flaw was found in Katello where the Content View History API does not properly enforce authorization when accessing a Content View specified by the user. An authenticated user with permission to view Content Views in one organization may be able to access the lifecycle history of a Content View belonging to another organization

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-79654