Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30836

Опубликовано: 19 мар. 2026
Источник: redhat
CVSS3: 10
EPSS Низкий

Описание

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

A flaw was found in Step CA, an online certificate authority. A remote attacker can exploit this vulnerability by sending an unauthenticated SCEP (Simple Certificate Enrollment Protocol) Update Request. This allows the attacker to issue unauthorized certificates, potentially leading to a compromise of the certificate management system and enabling further attacks such as impersonation or man-in-the-middle attacks.

Отчет

No Red Hat products are impacted. The affected component (Step CA) is not used or provided by any products.

Дополнительная информация

Статус:

Critical
Дефект:
CWE-306
https://bugzilla.redhat.com/show_bug.cgi?id=2449211github.com/smallstep/certificates: Step CA: Unauthenticated certificate issuance via SCEP Update Request

EPSS

Процентиль: 22%
0.00296
Низкий

10 Critical

CVSS3

Связанные уязвимости

CVSS3: 10
ubuntu
5 месяцев назад

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

CVSS3: 10
nvd
5 месяцев назад

Step CA is an online certificate authority for secure, automated certificate management for DevOps. Versions 0.30.0-rc6 and below do not safeguard against unauthenticated certificate issuance through the SCEP UpdateReq. This issue has been fixed in version 0.30.0.

CVSS3: 10
github
5 месяцев назад

step-ca has Unauthenticated Certificate Issuance via SCEP UpdateReq (MessageType=18)

EPSS

Процентиль: 22%
0.00296
Низкий

10 Critical

CVSS3