Foreman 3.18.2 is now available

This release addresses four security vulnerabilities:

  • CVE-2026-5136 — privilege escalation via usergroup role assignment allowing users to grant themselves arbitrary roles
  • CVE-2026-5142 — cross-tenant private SSH key disclosure through a taxonomy scoping bypass in the KeyPairs controller
  • CVE-2026-5135 — unauthorized modification of host configurations via lookup value override retargeting
  • CVE-2026-5138 — information disclosure allowing cross-tenant metadata leaks through improper validation of nested request parameters

All users are strongly encouraged to upgrade. For full details, see the Foreman security page.

Packages may be found in the 3.18 directories on both deb.theforeman.org and yum.theforeman.org, and tarballs are on downloads.theforeman.org.

The GPG key used for signing RPMs and tarballs has the following fingerprint:
CAB7B75A67A3DE88F9F76C3728D5752EFF70B304

The GPG key used for signing DEBs has the following fingerprint:
5B7C3E5A735BCB4D615829DC0BDDA991FD7AAC8A.