Cobbler on Red Hat contains a flaw related to template_api.py's failure to disable the Cheetah template engine's capability to execute Python statements contained in templates. The issue is triggered when a remote, authenticated administrator uses a crafted kickstart template file, allowing for the execution of arbitrary code.
Upgrade to version 2.0.7 or higher, as it has been reported to fix this vulnerability. In addition, Red Hat has released a patch for some older versions.