CVE-2026-0980 HIGH

CVE-2026-0980: Rubyipmi: red hat satellite: remote code execution in rubyipmi via malicious bmc username

Vendor Red Hat
Product Red Hat Satellite 6
Weakness CWE-78
Published February 27, 2026
Last update March 26, 2026

CVSS base score

8.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.

Key dates

02Disclosure timeline

February 27, 2026 CVE published
March 26, 2026 Record updated