VYPR

foreman-mcp-server

by Red Hat

CVEs (2)

  • CVE-2026-12112HigJun 23, 2026
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of authenticated client connections, by trusting a non-secret session ID without…

  • CVE-2026-9073MedJun 23, 2026
    risk 0.40cvss 6.2epss 0.00

    A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication credentials, at an informational level. The…