Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17039

Опубликовано: 24 июл. 2026
Источник: redhat
CVSS3: 3.1
EPSS Низкий

Описание

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

Отчет

Red Hat Product Security assessed this issue as having Low impact. The certificate authority (CA) renewal request path does not perform the same realm-based authorization check as the enrollment path, which is a genuine authorization gap. However, exploitation additionally requires a non-default, though supported, deployment configuration: a realm-mapped authorization manager configured for multi-tenant or delegated sub-CA (MSP-style) use. Deployments that do not configure this feature are not exposed to this issue. Direct testing was performed to determine the practical consequences of the confirmed bypass rather than relying on the authorization gap alone to drive severity. That testing found no confidentiality impact, since the resulting certificate's content is already retrievable by any user through the product's own standard, intended certificate-lookup functionality, independent of this issue. No private key material is exposed at any point, so the issue cannot be used for impersonation. The victim's original certificate and their own ability to renew it are both unaffected, and revocation requires a separate, unrelated authentication mechanism this issue does not touch, so there is no denial-of-service capability. The concrete, demonstrated impact is limited to the creation of one additional, correctly and non-deceptively attributed certificate record outside the issuing realm's approval.

Меры по смягчению последствий

Deployments that do not configure a realm-mapped authorization manager (AuthzRealmDefault with a non-default realm-to-authorization-manager mapping) for multi-tenant or delegated sub-CA use are not exposed to this issue. For deployments that do use realm-based authorization, using a renewal profile that additionally restricts renewal requests to the original requester narrows exposure: the shipped caDirUserRenewal.cfg profile configures authz.acl=user_origreq="auth_token.uid", which independently blocks cross-user renewal by comparing the renewing caller's UID against the UID that submitted the original request. This is a partial mitigation only -- it is realm-blind rather than realm-aware, so a UID collision across two independently-administered realms' user directories would still bypass it -- and it does not apply to caManualRenewal.cfg or other shipped renewal profiles that configure no authz.acl, which remain exploitable as described. No complete mitigation is available; apply the update once released.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pkiFix deferred
Red Hat Certificate System 11redhat-pkiFix deferred
Red Hat Certificate System 9pki-coreFix deferred
Red Hat Enterprise Linux 10dogtag-pkiFix deferred
Red Hat Enterprise Linux 6pki-coreFix deferred
Red Hat Enterprise Linux 7pki-coreFix deferred
Red Hat Enterprise Linux 8pki-coreFix deferred
Red Hat Enterprise Linux 9pki-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2506720pki-core: dogtag-pki: redhat-pki: pki-core: CA renewal request processing omits realm authorization check performed by enrollment path

EPSS

Процентиль: 12%
0.00211
Низкий

3.1 Low

CVSS3

Связанные уязвимости

CVSS3: 3.1
ubuntu
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

CVSS3: 3.1
nvd
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

CVSS3: 3.1
debian
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal r ...

CVSS3: 3.1
github
24 дня назад

A flaw was found in pki-core. The certificate authority (CA) renewal request path does not perform the realm-based authorization check that the enrollment path performs, allowing an authenticated user entitled to one realm to cause a certificate belonging to a different realm to be renewed without that realm's authorization.

EPSS

Процентиль: 12%
0.00211
Низкий

3.1 Low

CVSS3