Threat · curated 28 Jul 2026

CVE-2026-12112 - Red Hat Customer Portal

Coverage timeline

28 Jul 2026redhat.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-12112 shows how weak session handling in an MCP server exposes AI agent infrastructure to unauthenticated session hijacking and full code execution, a critical risk as organizations deploy MCP-based tooling.

CVE-2026-12112 is a session management flaw in the foreman-mcp-server (MCP Server) shipped with Red Hat Satellite 6.18 and 6.19, where unauthenticated attackers can hijack active administrative sessions because the server caches authenticated client connections and trusts a non-secret session ID without re-validating authentication tokens, while also logging newly created session IDs to standard logs. Rated 7.8 CVSS v3 (Important), it can lead to privilege escalation and infrastructure-wide code execution; Red Hat has issued fixes via RHSA-2026:28405 and RHSA-2026:28438.