A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Red Hat
Red Hat red Hat Satellite 6 |
|
| Vendors & Products |
Red Hat
Red Hat red Hat Satellite 6 |
Fri, 27 Feb 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system. | |
| Title | Rubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc username | |
| First Time appeared |
Redhat
Redhat satellite |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:satellite:6 | |
| Vendors & Products |
Redhat
Redhat satellite |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2026-02-27T07:30:42.657Z
Updated: 2026-02-27T07:30:42.657Z
Reserved: 2026-01-15T08:53:56.962Z
Link: CVE-2026-0980
No data.
Status : Awaiting Analysis
Published: 2026-02-27T08:17:09.647
Modified: 2026-02-27T14:06:37.987
Link: CVE-2026-0980
No data.