Threat · curated 28 Jul 2026
CVE-2026-12112 - Red Hat Customer Portal
First reported redhat.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
CVE-2026-12112 shows how weak session handling in an MCP server exposes AI agent infrastructure to unauthenticated session hijacking and full code execution, a critical risk as organizations deploy MCP-based tooling.
CVE-2026-12112 is a session management flaw in the foreman-mcp-server (MCP Server) shipped with Red Hat Satellite 6.18 and 6.19, where unauthenticated attackers can hijack active administrative sessions because the server caches authenticated client connections and trusts a non-secret session ID without re-validating authentication tokens, while also logging newly created session IDs to standard logs. Rated 7.8 CVSS v3 (Important), it can lead to privilege escalation and infrastructure-wide code execution; Red Hat has issued fixes via RHSA-2026:28405 and RHSA-2026:28438.