Foreman prior to 1.9.0 allows remote authenticated users with the edit_users permission to edit administrator users and change their passwords via unspecified vectors.
It was discovered that in Foreman the edit_users permissions (for example, granted to the Manager role) allowed the user to edit admin user passwords An attacker with the edit_users permissions could use this flaw to access an admin user account, leading to an escalation of privileges ...