Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18047

Опубликовано: 28 июл. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

Отчет

Red Hat rates this as Moderate because the impact of the authentication bypass is limited in scope and consequence. The vulnerability only affects the ACME enable/disable admin endpoints — other PKI subsystems (CA, KRA, OCSP, TPS) enforce authorization at the application layer and are not affected by this flaw. An attacker who exploits this flaw can only toggle the ACME service on or off. While re-enabling a disabled ACME service restores the full ACME protocol stack, certificate issuance through ACME still requires completing the standard RFC 8555 challenge-response flow, including proof of domain control — the enable/disable bypass alone does not grant the ability to obtain certificates. The ACME responder requires explicit installation and deployment and is not present in default PKI server configurations.

Меры по смягчению последствий

To mitigate this vulnerability, change the URL patterns in the ACME responder's web.xml from exact-match to prefix-match. Edit the file /usr/share/pki/acme/webapps/acme/WEB-INF/web.xml and replace the url-pattern entries for the enable and disable endpoints: /enable -> /enable/ /disable -> /disable/ Then restart the PKI server for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pki:10/redhat-pkiFix deferred
Red Hat Certificate System 11redhat-pkiFix deferred
Red Hat Certificate System 9pki-coreOut of support scope
Red Hat Certificate System 9redhat-pkiOut of support scope
Red Hat Enterprise Linux 10dogtag-pkiFix deferred
Red Hat Enterprise Linux 6pki-coreOut of support scope
Red Hat Enterprise Linux 7pki-coreFix deferred
Red Hat Enterprise Linux 8pki-core:10.6/pki-coreFix deferred
Red Hat Enterprise Linux 9pki-coreFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-288
https://bugzilla.redhat.com/show_bug.cgi?id=2507956dogtag-pki: pki-core: redhat-pki: pki: ACME admin enable/disable endpoint authentication bypass via trailing slash

EPSS

Процентиль: 21%
0.00281
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
20 дней назад

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

CVSS3: 6.5
nvd
20 дней назад

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

CVSS3: 6.5
debian
20 дней назад

A flaw was found in Dogtag PKI's ACME responder where the web.xml secu ...

CVSS3: 6.5
github
20 дней назад

A flaw was found in Dogtag PKI's ACME responder where the web.xml security constraints use exact URL pattern matching for admin-only enable/disable endpoints. By appending a trailing slash to the URL, an unauthenticated attacker can bypass the Tomcat authentication constraint while RESTEasy still routes the request to the handler, allowing unauthorized toggling of the ACME service state including persistent denial of service.

EPSS

Процентиль: 21%
0.00281
Низкий

6.5 Medium

CVSS3