Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76561

Опубликовано: 07 сент. 2026
Источник: redhat
CVSS3: 7.2

Описание

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

Отчет

Exploitation of this flaw requires an existing CA-Administrator-equivalent account; it is not exploitable by an anonymous or unprivileged user on its own. This precondition is already reflected in the CVSS vector via Privileges Required: High. The integrated Dogtag certificate authority is enabled by default in a standard ipa-server-install deployment, and certificate profile import is a routine, expected CA Administrator operation. Once that precondition is met, exploitation is deterministic and reaches full code execution as pkiuser, with further escalation to root observed in tested environments. On its own, this flaw provides a privilege-escalation path from CA Administrator to host-level code execution

Меры по смягчению последствий

Until a fixed package is available, restrict membership in CA Administrator and equivalent roles to fully trusted operators, and audit certificate profile import operations for unexpected or unrecognized profile content. Review any custom ExternalProcessConstraint executable configuration in Dogtag for unnecessary exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 9pki-coreAffected
Red Hat Enterprise Linux 10dogtag-pkiAffected
Red Hat Enterprise Linux 6pki-coreOut of support scope
Red Hat Enterprise Linux 7pki-coreAffected
Red Hat Enterprise Linux 8pki-coreAffected
Red Hat Enterprise Linux 8pki-core:10.6/pki-coreAffected
Red Hat Enterprise Linux 9pki-coreAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2519523pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint)

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
ubuntu
10 дней назад

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

CVSS3: 7.2
nvd
10 дней назад

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

CVSS3: 7.2
debian
10 дней назад

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate autho ...

CVSS3: 7.2
github
10 дней назад

A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile content beyond the profile ID. An authenticated user with CA Administrator privileges can exploit Dogtag's ExternalProcessConstraint mechanism to execute arbitrary commands with attacker-controlled environment variables, achieving code execution as the pkiuser account.

7.2 High

CVSS3