A vulnerability in SUSE Manager allows root operations to be executed without authentication.

A vulnerability (CVE-2025-46811) has been identified in the SUSE Manager toolkit, intended for centralized management of IT infrastructure using various Linux distributions. This vulnerability allows commands to be executed on any systems managed through SUSE Manager without authentication. The commands are executed with root privileges, enabling complete control over the entire infrastructure. The issue has been assigned a critical severity level (9.3 out of 10).

The vulnerability is caused by the presence of a handler that accepts commands via the WebSocket protocol (call “/rhn/websocket/minion/remote-commands”) without restricting access. Any user who can send packets to network port 443 on server SUSE Manager can execute arbitrary commands with root privileges on all systems managed through SUSE Manager. To access without authentication, it is sufficient to simply not send the SessionId when forming the request.

The issue manifests in both separately distributed builds of SUSE Manager and in installation images and containers of SUSE Linux supplied with SUSE Manager (e.g., SLES15-SP4-Manager-Server). The vulnerability is present up to version SUSE Manager 5.0.4.1 and has been fixed in updates 4.3.16 and 5.0.5.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster