Red Hat Product Errata RHSA-2026:35837 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35837 - Security Advisory Overview Updated Packages Synopsis Important: fence-agents security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for fence-agents is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The fence-agents packages provide a collection of scripts for handling remote power management for cluster devices. They allow failed or unreachable nodes to be forcibly restarted and removed from the cluster. Security Fix(es): python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens (CVE-2026-48526) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux High Availability for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux High Availability for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - 4 years of updates 9.2 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - 4 years of updates 9.2 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux High Availability for x86_64 - Advanced Update Support 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux High Availability for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux High Availability for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux High Availability for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux High Availability for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux Resilient Storage for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux Resilient Storage for IBM z Systems - Extended Life Cycle 9.2 s390x Red Hat Enterprise Linux Resilient Storage for x86_64 - Extended Life Cycle 9.2 x86_64 Fixes BZ - 2482734 - CVE-2026-48526 python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens CVEs CVE-2026-48526 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM fence-agents-4.10.0-43.el9_2.23.src.rpm SHA-256: 4888eb45887d8c49ec45c0e817f808270d492ef134e9afd7683f62eb737cb333 x86_64 fence-agents-common-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 30469dec252dc761990d5aeaac7a62e02d6bb155f6af3b5ba4598d2089a09133 fence-agents-compute-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: e7ca4a7ab1972ce2011dbc2706665db03a9dffecde8503c12d1ee866aef45e5b fence-agents-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 0a1763580bab18fbe9cf75b0767bf0d4c4e69e9d2596faaa7844e15902ed312c fence-agents-debugsource-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: bde2ea4a2ee7cf80eaf9886e324c2c24a9e6d8756da710697e87d0567e9784f3 fence-agents-ibm-powervs-4.10.0-43.el9_2.23.noarch.rpm SHA-256: d1d81f089ab5f8a7e427fddf55af5525627b86d9800b955dfb7b2ce16000a2bb fence-agents-ibm-vpc-4.10.0-43.el9_2.23.noarch.rpm SHA-256: afe06c29980b3c8eb3b1ed5f7140b110193c7beb14b49cadafc24d291c611200 fence-agents-kdump-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 19b04b1c6d0d162769e6c8b1473fa1af23462924b871195ec7c6028bd23036df fence-agents-kubevirt-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 5467d5db677d70575f0c595a707914b5e3e0b552141cb80723e877ce20a6d8e7 fence-agents-kubevirt-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: d8b07826d740d9fbac903a91ea4fa3a7f5db54a366707bb48c1ab95472975e24 fence-agents-virsh-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 6d0ee810d70fc90111d04f032ae79440ae62650da4a04f874280088bd9b276b8 fence-virt-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 05014f718481e65fddba5370959b2c12313c491c1ba7f31a02cbf518f39b5ae6 fence-virt-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 7a77c5f0f2bc4ca596f102206ff73db480edce0c46c6810c528ea8d65a19ec85 fence-virtd-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 1e00b81d0f49911c625cbc79fc10a9f9a8f517451f7b32ae6bd2d0fee95f8944 fence-virtd-cpg-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: f406675c7a89c0506b99bd8d757080d59326a04f4b316a32051e306368b7b383 fence-virtd-cpg-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: c57321b747f8eb373690e248d5a0d858bf0969074b5898a71df2243477a1df14 fence-virtd-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: b6cf8d0f3c1df2ac1612108bb58e8ea1dab481066ff2ba2c994266b725dffb95 fence-virtd-libvirt-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 859be6b606d814036dcc092b8b5f71cf8021d5abac231bd6107a80c9f4bdcce3 fence-virtd-libvirt-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: ab535b886b628cb89b2d8c08f8c58d6cf84fbeb5507fd28ff2f843d507de8a49 fence-virtd-multicast-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: cf317aafcfc1c890a34de06dc131b03b7a52df50f4f0fbd026e2617398838b29 fence-virtd-multicast-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: ef22b565ae893e11074314828c782a62da5de24755c7ee3d9a529630847225c6 fence-virtd-serial-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: 906a6d0f1fe93ee3cf96cc8ce0f22f40ca968eda5c530fdd32b34da9a31c438b fence-virtd-serial-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: c30fdfd285b8eb76e49933f1b03c72faba97ba4eb747ef0e09a57f0e44a29bbe fence-virtd-tcp-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: c583eb8da1b40caad0b71858c8292cd2ba1a32373ba6e6a9c88278573bc1799d fence-virtd-tcp-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: b0e464315cfd3c39d3d086687f307084834145f548fd6fe7de2ac2507ba5cf2a ha-cloud-support-debuginfo-4.10.0-43.el9_2.23.x86_64.rpm SHA-256: b2465fb3776561271fecd224cc931545c813527fe6ef776141f0d6aa6c2dee40 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM fence-agents-4.10.0-43.el9_2.23.src.rpm SHA-256: 4888eb45887d8c49ec45c0e817f808270d492ef134e9afd7683f62eb737cb333 ppc64le fence-agents-common-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 30469dec252dc761990d5aeaac7a62e02d6bb155f6af3b5ba4598d2089a09133 fence-agents-compute-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: 63c11ac562a0d7d4bc9ddcf4050a6a06fe21744d947b8856f0d62d11d1387227 fence-agents-debuginfo-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: d6a82c569e279f7a5fd17eda3d79dfad0f3cfed6a68bc2978a63e5d2260a291c fence-agents-debugsource-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: f16a2c63fcaf07d7f1e3146640a7086f55a65221bf7eb093b9cfe04776523463 fence-agents-ibm-powervs-4.10.0-43.el9_2.23.noarch.rpm SHA-256: d1d81f089ab5f8a7e427fddf55af5525627b86d9800b955dfb7b2ce16000a2bb fence-agents-ibm-vpc-4.10.0-43.el9_2.23.noarch.rpm SHA-256: afe06c29980b3c8eb3b1ed5f7140b110193c7beb14b49cadafc24d291c611200 fence-agents-kdump-debuginfo-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: 96fcc936493f54125642b650f2702a6f95c94614d60d146da673d5522cabecc7 fence-agents-kubevirt-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: d9d802ab62da7d0bc25b0bdf58da92736e77894000a1ead6e4c567b4910dfa60 fence-agents-kubevirt-debuginfo-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: 850c7e7a68ef9c7210703482c05750d20c1a86f92a073484104baaa951547bf2 fence-agents-virsh-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 6d0ee810d70fc90111d04f032ae79440ae62650da4a04f874280088bd9b276b8 Red Hat Enterprise Linux High Availability for Power LE - Update Services for SAP Solutions 9.2 SRPM ppc64le fence-agents-all-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: b76d44d33c53d3b4ee4b7171d911688f3e6ba8f466b81d7ae22d628c3ff6ae33 fence-agents-amt-ws-4.10.0-43.el9_2.23.noarch.rpm SHA-256: a4c43b6e5226d2c100c4490f28a209700af71a502452a9f9b2e7f1383bfefc92 fence-agents-apc-4.10.0-43.el9_2.23.noarch.rpm SHA-256: cf3d409f6a7cc6df75e4c65c7b49d7b77f81b99326920e0ead9f3b253f9da431 fence-agents-apc-snmp-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 3ca40905d307f80eccdfba75e09cf8c8de33bc27244821082aa4f1216cff1df7 fence-agents-bladecenter-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 4cb4f6985cf03b46a3f6ba74f6a4fc42fc08687d464411c9e4c1aa9ed640bff9 fence-agents-brocade-4.10.0-43.el9_2.23.noarch.rpm SHA-256: e1ae881cfb681d3c00cfe79f79fd3bd6b78581c092141e0581bed00894ad6d3c fence-agents-cisco-mds-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 8e1eda33bfb44afa259ccd476e4c3621aaa8b0ff041f6e36a067e34b10faf926 fence-agents-cisco-ucs-4.10.0-43.el9_2.23.noarch.rpm SHA-256: 89d975166720d8394f81626fe1bb0db1c902172e3c848d86e22fe097030fa1bd fence-agents-debuginfo-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: d6a82c569e279f7a5fd17eda3d79dfad0f3cfed6a68bc2978a63e5d2260a291c fence-agents-debugsource-4.10.0-43.el9_2.23.ppc64le.rpm SHA-256: f16a2c63fcaf07d7f1e3146640a7086f55a652
A critical authentication bypass vulnerability (CVE-2026-48526, CVSS 7.4 HIGH) in PyJWT allows attackers to forge valid JSON Web Tokens. The vulnerability affects the `fence-agents` package for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions, which includes PyJWT versions prior to 2.13.0. The fix requires updating the underlying PyJWT library to version 2.13.0 via the provided Red Hat security update.