This release addresses four security vulnerabilities:
- CVE-2026-5136 — privilege escalation via usergroup role assignment allowing users to grant themselves arbitrary roles
- CVE-2026-5142 — cross-tenant private SSH key disclosure through a taxonomy scoping bypass in the KeyPairs controller
- CVE-2026-5135 — unauthorized modification of host configurations via lookup value override retargeting
- CVE-2026-5138 — information disclosure allowing cross-tenant metadata leaks through improper validation of nested request parameters
All users are strongly encouraged to upgrade. For full details, see the Foreman security page.
Packages may be found in the 3.19 directories on both deb.theforeman.org and yum.theforeman.org, and tarballs are on downloads.theforeman.org.
The GPG key used for signing RPMs and tarballs has the following fingerprint:
9E0B13B8AF9E5CFCC1306EFE481C109CB4CA6B3F
The GPG key used for signing DEBs has the following fingerprint:
5B7C3E5A735BCB4D615829DC0BDDA991FD7AAC8A.