CVE-2026-0980
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2026-0980, https://github.com/logicminds/rubyipmi/commit/252503a7b4dca68388165883b0322024e344a215, https://access.redhat.com/errata/RHSA-2026:5968, https://access.redhat.com/errata/RHSA-2026:5970, https://access.redhat.com/errata/RHSA-2026:5971, https://access.redhat.com/security/cve/CVE-2026-0980, https://bugzilla.redhat.com/show_bug.cgi?id=2429874, https://github.com/logicminds/rubyipmi, https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rubyipmi/CVE-2026-0980.yml
