This release addresses eight security vulnerabilities:
- CVE-2026-96658 — Safemode bypass allowing a low-privilege user who can render template content to reach Ruby code execution (critical)
- CVE-2026-96659 — excessive Viewer role permissions on template preview, which can lead to code execution when Safemode is disabled or bypassed
- CVE-2026-12423 — provisioning token validation flaw allowing unauthenticated access to build-host provisioning data through an IP/MAC fallback
- CVE-2026-12540 — command injection in the
foreman-rake errors:fetch_logtask - CVE-2026-12541 — command injection in
foreman-rakedatabase tasks - CVE-2026-12542 — command injection in
foreman-tail - CVE-2026-12544 — template injection and unsafe deserialization in
foreman-rakeconfiguration loading - CVE-2026-12545 — editor command injection in Hammer CLI (fixed in Hammer CLI 3.19.1)
All users are strongly encouraged to upgrade. For full details, see the Foreman security page.
This release also bumps Safemode to 2.0 and fixes bulk actions being applied to hosts in a different location than the one selected.
Packages may be found in the 3.19 directories on both deb.theforeman.org and yum.theforeman.org, and tarballs are on downloads.theforeman.org.
The GPG key used for signing RPMs and tarballs has the following fingerprint:
9E0B13B8AF9E5CFCC1306EFE481C109CB4CA6B3F
The GPG key used for signing DEBs has the following fingerprint:
5B7C3E5A735BCB4D615829DC0BDDA991FD7AAC8A.